User Suspension
Block an account now, keep everything needed to restore it later.
What it adds
A reversible suspension state that halts access immediately without deleting data or memberships.
What your agent is told to do
6
What your agent is told to do
6-
1
Make suspension a state on the account, not a deletion or a role change. Memberships, roles, and owned records stay exactly as they were.
-
2
Revoke every active session and API credential the moment suspension takes effect. A suspended user who stays signed in until their cookie expires is not suspended.
-
3
Decide explicitly what happens to that user's background jobs, scheduled tasks, webhooks, and shared links, and enforce that decision — leaving them running is a real gap, and stopping them silently breaks other people's work.
-
4
Show the suspended user a plain, calm screen explaining they cannot sign in and who to contact. Do not show them the internal reason or the admin's note.
-
5
Record who suspended whom, when, and why, and require a reason. Suspension without an audit trail is indistinguishable from a bug.
-
6
Do NOT let suspension be a way around deletion requests. If a user asked to be deleted, suspension is not the answer.
Edge cases it handles
7
Edge cases it handles
7- Content owned by a suspended user must have a defined visibility rule — hidden, retained, or attributed but locked — and it must be consistent across the app, search, and exports.
- Suspending a member must not orphan the organization: block the suspension of a last owner, or force a transfer first.
- Reinstatement must restore the previous roles and memberships exactly, not re-create them at a default level.
- If the seat rule frees a seat on suspension, reinstatement can fail on a full plan — surface that before the admin suspends, not after.
- A suspended account must not be able to reset its password, accept invitations, or re-register with the same email as a route back in.
- Notification of suspension is a product decision, not an accident — decide whether the user is emailed, and use the same rule every time.
- Suspension must be reversible by a different admin than the one who applied it, in case the suspending admin is the problem.
Definition of done
9
Definition of done
9- Suspension halts sign-in and revokes all sessions and API credentials immediately.
- No data, membership, or role is destroyed by suspending.
- The suspended user sees a clear message with no internal reasons.
- Every suspension and reinstatement is audited with an actor and a reason.
- Reinstatement restores prior roles and memberships exactly.
- Background jobs, webhooks, and owned content follow a documented rule.
- A suspended account has no alternate route back in via reset, invite, or re-registration.
- The feature matches the existing design system.
- No existing functionality is broken.
Related features
Content Reporting
Content Reporting
Let users flag content that needs a human to look at it.
What it does
A reporting flow that captures a reason, a snapshot of context, and enough signal for a moderator — without exposing the reporter.
How it works
- 1 Add a report action to every user-generated surface: posts, comments, profiles, files, messages. Offer a short list of concrete reasons plus an optional free-text field.
- 2 Capture the context a moderator needs at the moment of reporting — the content ID, its current body, the author, and a timestamp — so the review is not dependent on the content still existing.
- 3 Give the reporter an immediate self-serve action alongside the report: hide this item, mute this author, or both. A report that takes hours to review leaves the user staring at the thing they reported.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/content-reporting
Maintenance Mode
Maintenance Mode
Pause the app on purpose instead of serving a generic 500.
What it does
An operator-controlled outage window that shows a real maintenance page, lets staff through, and tells API clients the truth.
How it works
- 1 Make the mode a runtime flag an operator can flip without a deploy, and store it somewhere that stays reachable when the database is the thing being maintained.
- 2 Allowlist bypass for authenticated staff and for the health check endpoint, so the people fixing the problem can still use the app and the load balancer does not remove every instance.
- 3 Return 503 with a Retry-After header for API and crawler requests, and render the maintenance page for browsers. A 200 on a maintenance page tells search engines your content is now an apology.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/maintenance-mode
Audit Log
Audit Log
Know who did what, and when.
What it does
An append-only record of security- and data-sensitive actions.
How it works
- 1 Log the actions that matter: sign-ins, permission changes, deletions, exports, billing changes, admin actions.
- 2 Capture actor, action, target, timestamp, and IP.
- 3 Make it append-only. An audit log that can be edited is not an audit log.
Copy the prompt
No account needed
Add this feature to my app:
https://addthisfeature.com/x/audit-log
How it works
-
1
Copy the link
Grab the Markdown instruction URL for this feature.
-
2
Give it to your AI
Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.
-
3
It inspects, then implements
Your agent reads your existing app first, then adds the feature to fit it.
Works with your stack
These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.
Need it tighter than that? Customize the feature and tell it exactly what you're running.