Words
Every screen uses one name for each thing. The words live in engine/config/locales/en/ and
server/app/frontend/manage/. A few words differ between the two audiences: managers in
/manage, and people on the sign-in pages, their account page, and the mail masks sends.
One name each
Section titled “One name each”| Say | Not | |
|---|---|---|
| activity | audit log, history, events | every list of events, newest first |
| client | application | in /manage, where OAuth is the subject |
| app | application, client | to people, who allow an app in |
| actor, actors | person, people, user | in /manage |
| account | actor, user | what a person has, and on their own pages |
| manager | admin, whoever runs this server | somebody holding masks:manage |
| server | instance, installation | the thing a person signs in to |
manage, /manage |
console, dashboard, admin panel | where managers work. A screen says Manage demo, and the docs say /manage. |
| confirm, confirmation | verify, verification | proving an email address or a phone number |
| photo | picture, avatar | the uploaded image. Identicons and initials are drawn. |
| passkey | fingerprint, face or PIN | |
| authenticator app | authenticator, OTP, TOTP | |
| second factor | second step, 2FA, MFA | |
| provider | identity provider, IdP, SSO | somewhere else people sign in with. Identity provider appears only on a SAML provider’s page, where it is SAML’s own term. |
| connected account | connection, linked account | an account elsewhere linked through a provider |
| connect | link | what somebody does to add a connected account |
| delegation | broker, token vault, grant | in /manage and the docs, an app allowed to use one connected account |
| can use it while you are away | delegated, has access | to people, about an app holding a delegation |
| stop | revoke | what a person does to end a delegation |
| policy | sign-in policy, rules | a sign-in policy, once the context is sign-in |
| IP address | address | an address alone means an email address |
| user agent | agent, UA | |
| refused | turned away, rejected, denied | a request masks would not serve |
| revoked | cut off, ended | a session, token, or consent taken away |
| blocked | banned | a device that is refused from then on |
| registered | created | a client |
| journey | flow, context, trigger | what an email was sent from: a sign-in to an app, the account page, a manager, or masks on its own |
actor is the model’s name in code, in the GraphQL schema, and in the concept pages, and /manage
uses the same word. Outside /manage, a screen says account.
Verbs and nouns
Section titled “Verbs and nouns”Sign in, sign out, and sign up are verbs. Sign-in, sign-out, and signup are nouns. A button says Sign in, a chart counts sign-ins, and a policy decides whether signup is open.
Events
Section titled “Events”An event’s label is written once, in events.yml, and served to /manage as label on Event
and EventAction. The account page reads the same file. A label is a noun and a past participle,
such as Passkey added, Client archived, or Device sign-in refused. A change is always
changed, and no label says edited or updated.
Buttons and empty lists
Section titled “Buttons and empty lists”A page’s add button names what it adds: Add actor, Add policy, Add provider, Add adapter. The form’s own submit is Add or Save.
A list with nothing in it says Nothing yet., or None. where nothing will ever arrive on its own. A link to more of a list says All activity.