BCINexus · Start here
Accounts & roles
One account covers the website and the desktop app. Roles decide what you administer; capabilities decide what you may do as a researcher or reviewer. They are deliberately separate.
Creating an account
- 1
Register with email or a provider
Sign up with an email address and password, or use Google or ORCID. ORCID is worth using if you publish: signing in with it verifies your ORCID identifier on your profile, which then travels with your author byline.
- 2
Verify your email
Email-registered accounts must confirm the address before the dashboard opens. If the message does not arrive, request another from the verification screen and check spam filters for mail from bcinexus.xyz.
- 3
Complete your profile
Name, institution, and research interests are what other researchers see, and what reviewer matching reads when a submission needs someone with your expertise.
- 4
Sign in from the desktop app
BCILattice signs in with the same account. That is what enables sync, teams, and publishing — it does not start uploading your local data.
Roles and capabilities
Your account has exactly one role, and any number of capability flags layered on top. This matters because "reviewer" is not a role you can be promoted into at the expense of something else — it is a flag added to an ordinary account.
Roles
| Role | What it means |
|---|---|
| user | The default. Full researcher access: studies, datasets, models, teams, submissions. |
| admin | Moderation queue, reviewer administration, and platform operations. Implicitly has reviewer capability. |
| superadmin | Everything an admin can do, plus review pipeline configuration and governance actions. |
Capabilities
| Flag | How it is granted | What it unlocks |
|---|---|---|
is_reviewer | Approved reviewer application, or granted by an admin | The reviewer dashboard, the available pool, stage participation, and decision-making. |
is_researcher | Granted automatically the first time you publish | The researcher badge on your profile and inclusion in researcher directories. |
is_doctor | Set by an admin after credential checks | An identity marker only. It grants no permissions on its own — clinical work still needs a project role. |
Admins are reviewers by definition
Any check for reviewer capability treats admins and superadmins as qualifying, so an admin never needs the reviewer flag set explicitly to open a submission.
Account security
- Two-factor authentication
- Time-based one-time codes from any authenticator app. Enrol from account settings, confirm with a code, and store the backup codes somewhere safe — they are the only way back in if you lose the device. You can regenerate them at any time, which invalidates the old set.
- Sessions
- Every sign-in creates a session you can see and revoke individually from settings. "Revoke all" ends every session including the current one, which is the right move after a lost laptop.
- Lockout
- Repeated failed sign-ins temporarily lock the account. Waiting it out or resetting the password clears it.
- Password reset
- Requested by email and time-limited. Changing your password issues fresh tokens, so previously issued ones stop working.
Device activations
A paid plan includes a number of desktop seats. Activating BCILattice on a machine consumes one; deactivating it from account settings frees it again. Re-activating the same machine reuses its existing activation instead of burning a second seat.
- Machines are identified by a composite fingerprint hash, not by any hardware serial you have to hand over.
- If you are locked out because every seat is taken, deactivate an old device from the web dashboard — no support ticket needed.
- Licensing decisions are recorded in an append-only event log, which is what support looks at when a seat count seems wrong.
Deleting your account
Account deletion is available from settings. Published work is a different matter: once a study or dataset is part of the public record, other people may already be citing it, so removal is handled through the corrections and retraction process rather than by deleting the account.
Before deleting
Transfer ownership of any team or study that other people depend on, and export anything you want to keep. Deletion is not reversible from the web dashboard.
Something missing or out of date? Email support or request a doc page. Include the page name and what you expected to find.