This page now works with the User Management hub and Feature Shop direction. It reads the same permission truth area, explains why a user can or cannot do something, and stays read-only until the official schema/RLS/payment launch plan is ready.
Checking...
Reads sb_profiles only when owner/admin verified.
Inspector only.
Rail follows injected theme variables.
Feature Shop keeps the commercial ideas visible without real payment.
User Management owns real current profile changes and the delete request queue.
This page turns profile fields into clear allow/lock reasoning.
Real locks need database fields, RLS and route checks. HTML-only locks are not security.
This mirrors the Feature Shop plan/add-on direction, but remains read-only.
Main plan: free_viewer, creator_growth, creator_pro, studio_business, platform_owner.
active, limited, restricted, banned, review.
Per-feature add-on flags, creator gates, builder packs and storage/video packs.
Normal users must never self-update role, can_submit, plan or future paid fields.
Hard rules need database policies, not just page buttons.
User Management already reads audit history. Future permission changes need audit entries too.
This page does not update users, roles, plans, policies or billing.
It explains locks; it does not enforce final locks alone.
Payment-related features stay preview-only.
Account deletion remains in Profile request flow + User Management server-side action only.
V7.12.300.29 Permissions Inspector - global header/footer/theme helpers, theme rail, Supabase read-only profile reasoning, no writes.