Confirm Source Authorization Before You Connect
Authorization is a documented relationship among source owner, account, permitted users, purpose, scope, duration, and provider terms, not merely a usable credential.
In short: Identify the source owner, account administrator, Norva account, household users, purpose, scope, start date, expiry or review date, and revocation path. Check the source provider's terms and obtain approval through an appropriate channel. Keep minimal non-secret evidence, not credentials. A username that works, an address found online, prior household access, or another person's invitation does not by itself prove continuing authorization. When ownership or scope is unclear, stop and clarify.
Norva's terms require users to connect a compatible source they own or are authorized to use. This checklist supports factual verification and is not legal advice.
Identify the actual owner
Record the person or organization that controls the source account and who can authorize household access. Do not treat the person who remembers the password as the owner.
For an organization, follow its approved administrator and device policy rather than informal coworker permission.
Define who may use the connection
List the Norva account owner and household profiles that may access the source. Clarify whether permission applies to one person, household, device, location, or time period. Avoid extending a narrow approval to every household member.
The source connection planning guide maps these constraints into setup and device decisions.
Define purpose and scope
State that the connection is for organizing and playing authorized media through Norva on supported devices. Record any provider limits relevant to account sharing, remote access, downloads, or household use without paraphrasing them into broader permission.
If terms are unclear, ask the source provider or qualified adviser rather than interpreting silence as consent.
Check current terms and status
Record the source terms URL, retrieval date, account status, subscription or access status if relevant, and any authorization expiry. A prior agreement may no longer apply after household, employment, plan, or provider changes.
Do not include billing details in the authorization card.
Obtain clear approval
Use the source's supported family, sharing, or delegated-access controls where available. Otherwise obtain a clear instruction from the actual owner through an appropriate channel. Store only the date, scope, approver, and evidence location.
Never ask an owner to send a password or token as proof.
Keep credentials separate
Authorization evidence explains why access is permitted; credentials enable access. Store them separately with different protection. The secure source-details guide keeps passwords or tokens out of planning documents.
If access is revoked, delete or invalidate the credential through the source's official process.
Establish a review and revocation path
Choose an expiry or review date for permission that is not permanent by assumption. Know who can revoke access and what actions follow: disconnect the source, sign out devices, remove local media, and update the household register.
Review immediately after an owner, household, employment, device, plan, or policy change.
Ask the owner to confirm that the selected endpoint and account belong to the authorized service. Permission for an account does not make a look-alike hostname safe. Keep endpoint verification with the technical checklist, but resolve any mismatch before credentials are entered or catalog data is requested.
Verify before each new connection
Authorization for one source account does not automatically cover a second source, another account, or another endpoint. The one-source-at-a-time guide keeps each approval and technical change traceable.
Original evidence: source authorization evidence card
| Field | Non-secret evidence |
|---|---|
| Source owner | Name or role stored privately |
| Administrator | Authorized account manager |
| Norva account and profiles | Masked account and scope |
| Purpose | Authorized media organization and playback |
| Provider terms | URL and retrieval date |
| Approval | Date, approver, scope, evidence location |
| Review or expiry | Date or event |
| Revocation | Owner and official action path |
Common mistakes and limitations
- Treating a working password as permission.
- Extending one person's approval to an entire household.
- Ignoring source provider terms.
- Keeping approval indefinitely without review.
- Storing credentials beside authorization evidence.
- Assuming one source approval covers another.
- Making a legal conclusion from a generic checklist.
Frequently asked questions
Are valid credentials enough to prove authorization?
No. Credentials demonstrate possible access, while authorization comes from ownership, permission, scope, and applicable provider terms.
Can a household member authorize a source they do not own?
Do not assume so. Confirm authority with the actual owner or supported account administrator.
What happens when authorization ends?
Disconnect the source, revoke or remove credentials, review devices and local media, and record the closure through official controls.
Your next step
Read Norva's Current Source Terms