User investigation runbook
Use this runbook when one user reports missing access, incorrect plan state, model/feature differences, or account problems.
1. Confirm identity
Locate the exact Starfire account using the strongest available identifier. Do not assume two similar emails or display names refer to the same account.
Review verification and account state.
2. Confirm scope
Determine whether the issue occurs in:
- personal context
- one organization
- one project
- all contexts
Scope often identifies the permission layer immediately.
3. Check account state
Look for active restrictions, billing hold, security hold, suspension, or other state that can affect access.
4. Check organization membership
Verify:
- membership exists
- invitation was accepted
- role is correct
- required seat is available
- resource-level project/Knowledge access exists
5. Check plan and BillingAccount
Confirm the intended billing context, subscription, plan, credits, and entitlements are reconciled.
6. Check feature/model availability
Compare platform state, plan entitlement, organization policy, user override, rollout, and provider health.
Do not grant a broad admin role or model override until you know which layer denied access.
7. Check sessions/security
For authentication or suspicious-access reports, review sessions/devices and relevant security events.
8. Check request/run IDs
If the user has a request, build, research, or API failure, follow that exact resource into diagnostics instead of guessing from the visible message.
9. Make the smallest change
Prefer correcting the wrong state over adding a compensating exception.
Examples:
- fix membership rather than grant platform admin
- reconcile billing rather than manually grant a permanent plan
- refresh model policy rather than hard-allow every model
10. Verify as the affected scope
After the change, confirm the user/resource’s effective state. Administrator visibility alone does not prove the non-admin experience is fixed.
Do not use unrestricted content access as the default support workflow. Most account issues can be diagnosed from identity, permissions, billing, feature state, request IDs, and operational metadata.