Control plane
Users
Fork accounts
A Fork account identifies a person to the control plane. Organization membership and live authorization decide which spaces, settings, data views, and agent tools that account may use. Removing access takes effect on later protected requests; a copied URL is not an authorization grant.
Administrators can invite a person before a space exists and assign the intended organization role up front.
Application users
People who use an application inside a space are a separate concern from people who administer Fork. An app can use Fork authentication or its own sign-in system, but its backend must still enforce record-level and action-level authorization between its own users.
Identity in connectors
Composio connections belong to a verified application identity. Backends derive that identity from the signed-in user’s server-side session; browsers must not choose a subject or connected-account ID. See Composio connectors.