> ## Documentation Index
> Fetch the complete documentation index at: https://docs.botshield.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Managing accounts

> Use the Console registry to list, search, revoke and export Trusted Accounts, and see what the person controls in the BotShield app.

A binding has two sides. Your organization sees it in the **registry** in the BotShield Console. The person sees it in the **Trusted Accounts** list in the BotShield app. Either side can end it.

## The registry

In the [BotShield Console](https://console.botshield.ai), open **Trusted Accounts**. The **Registry** tab lists every binding for your organization. Use the **Development** and **Production** switch to choose the environment. A binding appears under the environment of the gate it came through.

The registry is a list of accounts, not of people. A row never shows an email address, a name, a device or another platform.

### Columns

| Column | Description |
| - | - |
| **Handle** | The opaque handle for this person on your platform: `OP_` followed by 12 characters. It is the value that `account.unlinked` carries. |
| **Trusted since** | When the person secured the account. |
| **Last pass** | When the human last passed on this account. |
| **Via gate** | The gate the person came through when they secured the account. |
| **Status** | **Notarized** for an active binding. **Unlinked**, with **by you** or **by human**, for a binding that ended. |

### Totals

| Tile | Counts |
| - | - |
| **Notarized** | Active bindings. |
| **New this period** | Bindings created in the selected period. |
| **Unlinked this period** | Bindings that ended in the selected period. |
| **Via gates** | Your Human Gates that have **Notarize account with BotShield** turned on. |

The period is **Last 30 days**, **90 days** or **All time**. The filters **All**, **Notarized** and **Unlinked** choose which rows the table shows.

### Search by your user reference

Type one of your own account IDs, the value you pass as `platform-user-ref`, into **Search by your user ref**. The match is exact. BotShield hashes what you type and compares it with the stored hash, then shows the row with its handle. Your reference is never stored in a readable form and never shown back to you.

This is how you find the handle for one of your users.

### Export CSV

**Export CSV** downloads the rows that are loaded in the table, with these columns: Handle, Trusted since, Last pass, Via gate, Status, Unlinked at, Unlinked by.

## Revoke

Select **Revoke** on an active row to end the binding. The Console asks **Stop trusting this account?** before it continues.

After a revoke:

| Where | What changes |
| - | - |
| The registry | The row's status becomes **Unlinked**, **by you**. The row stays in the list as a record. |
| Your webhook endpoint | Receives `account.unlinked` with `by: "platform"` and `reason: "platform"`. |
| The person | BotShield notifies the person in the BotShield app, with a push notification and an entry in the app's notification list. The app shows the account as unlinked. |
| Your page | On the person's next visit, the widget shows the offer again. Securing the account again creates a new binding with a new **Trusted since** date. |

Revoke an account when:

* The user deleted or closed the account on your side.
* The account changed hands.
* A sign-in detail changed, such as a password reset you did not expect, and you want the human to confirm again.

A revoke that finds no active binding succeeds and changes nothing.

## What the person controls

The person manages their side in the BotShield app, under **Trusted Accounts**.

| Action | What it does |
| - | - |
| **See the list** | Every account they secured, by platform name, with **Trusted since** and the date. |
| **Unlink** | Ends the binding. BotShield asks them to confirm first. Your endpoint receives `account.unlinked` with `by: "human"` and `reason: "human"`. |
| **Re-link** | Shown on an unlinked account. It opens a screen that names your platform and tells the person to open your site and tap **Link BotShield ID**. |

A person cannot secure an account again from the app alone. The request always starts on your page, where your sign-in shows which account it is. The app confirms the human. Your page identifies the account.

The person can type or scan a code in the app under **Link account**, but the code comes from your page.

## After an unlink

An unlinked account is an ordinary account again:

* A gate pass on it reports `trusted: false`.
* The widget shows the offer on the next visit, when the offer is on.
* Securing it again produces `gate.human_verified` with `first_time: true`.

Keep your own record in step by handling `account.unlinked`. See [Token and webhooks](/trusted-accounts/token-and-webhooks#account-unlinked).
