Skip to main content

Account and permission boundaries

Theseus has three independent identity domains. This page only helps you choose the right one; sign-in, permission, and configuration steps live in the section that owns each task.

Choose an account by task

TaskIdentity to useContinue with
Use Qixin AI, Portal, online licenses, personal or organization package sources, or Qixin cloud code servicesQixin accountQixin account and online services
Connect to, deploy to, or administer a runtime targetAn account owned by that runtime targetRuntime-target access and permissions
Identify the current operator on a runtime page and show or enable Page content by business roleAn App user owned by the current AppApp users, roles, and runtime-page sign-in

Boundaries to remember

  • The three identities can use the same username and still remain unlinked. They do not synchronize or inherit permissions.
  • Signing in to or out of Qixin does not sign in to or out of a runtime target and does not change the current App user.
  • Runtime-target administrator access applies only to that target. The App Admin role applies only inside that App.
  • After switching runtime targets, authorize access according to the new target's own rules. Neither Qixin sign-in nor an App user replaces it.
  • Configuring an App user does not grant online-service entitlements or runtime-target administration.

If the UI says you are signed in but lack permission, first identify which task produced the message, then use the corresponding page above. Do not try to bypass it with another account domain.