To separate digital skills account ownership authorization and security, define Tess's chosen task, device, account, content, audience, requested action, and source. Operating an interface differs from owning an account. Login help differs from authority to read messages, change credentials, accept terms, spend funds, or publish content. Accessibility, authentication, cybersecurity, legal authority, platform decisions, financial control, and clinical skill questions require distinct evidence and owners.
Define Tess's page-specific decision
To separate digital skills account ownership authorization and security, define the person, purpose, device, account, content, audience, authority, access, authentication, privacy, security, supporter, release condition, stop rule, recovery route, and control-return condition. Distinguish opening an app, composing a message, authenticating, recovering access, changing an account, approving payment, sharing location, moderating content, and authorizing supporter access.
Protect Tess's communication, secrets, and ownership
Tess's support plan keeps AAC, device access, emergency help, private content, credentials, recovery secrets, identity data, and funds protected under the authorized arrangement. Tess's digital-role boundary register cannot create account ownership, identity, platform permission, financial authority, cybersecurity, legal consent, or permission to inspect private content.
Build Tess's digital-role boundary register
Create one versioned record for the home and a community program. Include Tess's purposes, emergencies, devices, accounts, content, audiences, ownership, authentication, access, communication, privacy, payments, supporters, restrictions, incidents, recovery, outcomes, missingness, and reassessment evidence. Use one row per question with person goal, digital action, device, account, content, source, primary route, owner, urgency, uncertainty, evidence, and decision.
Validate Tess's counts and evidence
Reproduce 24 questions across eight routes: five skill, four access, three each for ownership, authentication, and privacy, and two each for security, payment, and support.
Connect Tess's evidence to a bounded action
Tess's team assigns one primary route and owner to every question. Behavioral assessment pauses when disputed ownership, an active compromise, missing access, or absent authorization determines the next action.
Work through Tess's example
Across 24 questions, five concern digital skill, four concern access, three concern account or content ownership, three concern authentication, three concern privacy, two concern cybersecurity, two concern payment authority, and two concern supporter authority. Preserve every planned and eligible unit, device and account version, authority, access, authentication, content and audience, communication, person choice, response, restriction, incident, recovery, repair, and endpoint. This fictional example supplies no account ownership, platform decision, identity determination, security assurance, treatment effect, compliance result, or promised outcome.
Address Tess's main interpretation risk
Calling all 24 digital deficits would erase ownership, access, security, privacy, financial, and role decisions. Categories cannot establish consent, legal authority, account control, cybersecurity, or treatment need. Review immediate danger, account and platform rules, ownership, authentication, accessibility, privacy, security, financial boundaries, communication, supporter response, instruction, restrictions, person priorities, incidents, burden, missingness, and design strength separately.
Set Tess's ABA scope and ethics boundaries
Tess's digital-role boundary register uses the CASP public summary only for high-level ABA behavioral-health-treatment scope for autistic people. The current BACB Ethics Code addresses competence, collaboration, consent and assent when applicable, confidentiality, assessment, risk, documentation, and evaluation for covered people. Device, account, platform, identity, cybersecurity, financial, emergency, safeguarding, employment, and legal authority remain with qualified owners.
Use CISA's four practices within Tess's real accounts
CISA Secure Our World emphasizes recognizing and reporting phishing, strong passwords and password managers, multifactor authentication, and prompt software updates. These are general security practices, not permission to access Tess's account, hold credentials, choose an authenticator, or override accessibility. The digital-role boundary register records which current service supports each control and who owns it.
Route suspicious messages through verified channels for Tess
The FTC phishing guide explains that deceptive emails and texts may seek passwords, account numbers, or other information. It advises contacting the company through a number or site already known to be real instead of using the message link. Tess's team may teach that bounded check with synthetic messages while leaving incident response, account action, and money decisions to authorized roles.
Use IdentityTheft.gov only after the right classification for Tess
IdentityTheft.gov recovery steps provide an FTC reporting and recovery route for U.S. identity theft, including contact with affected companies and credential changes. That route does not classify every suspicious message or authorize clinical staff to freeze accounts, access credit reports, file as Tess, or control funds. Preserve the person's authority and the qualified recovery owner.
Apply NIST digital-identity terms cautiously for Tess
Final NIST SP 800-63 Revision 4, released in July 2025, covers digital identity proofing, authentication, and federation for government information systems. It is a technical reference, not a universal consumer-account rule or clinical protocol. Tess's actual platform determines supported authenticators and recovery methods; account ownership, accessibility, risk, and delegated help remain separate decisions.
Treat cognitive accessibility as design evidence for Tess
The W3C cognitive-accessibility page distinguishes WCAG standards from supplemental informative guidance and describes needs involving perception, memory, language, attention, comprehension, and error correction. It cannot diagnose Tess, authorize account access, or guarantee usability. Testing for Tess uses the real interface, assistive technology, authentication, timing, and recovery path with the person.
Keep emergency action ahead of digital data for Tess
The National 911 Program says an emergency requiring immediate police, fire, or ambulance assistance belongs with 911 and that call-takers may provide instructions. Local systems differ, and the guidance is U.S.-specific. Tess's team follows qualified responders rather than completing a teaching trial, screenshot, percentage, or routine approval first.
Make digital communication accessible for Tess
The DOJ effective-communication guidance explains that covered entities consider the nature, length, complexity, context, and person's usual communication method. Platforms and account owners can have separate duties. Communication checks in Tess's digital-role boundary register cover instructions, authentication, messages, warnings, reports, and recovery explanations while sending provider-access decisions to the responsible entity.
Preserve Tess's AAC and authorship
The ASHA AAC portal says AAC users should always have access to their communication tools or devices. Tess's primary and tested backup communication remain available during login, messaging, support, recovery, compromise, and emergencies. A supporter may facilitate access without supplying Tess's message, consent, audience, account answer, payment choice, or incident report.
Use technology evidence cautiously for Tess
A systematic review of assistive technology for practical skills included 18 studies involving autistic people or people with intellectual disabilities across varied targets and tools. It cannot establish that an app, reminder, password manager, passkey, filter, tracker, communication device, or recovery aid will teach Tess's skill, prevent compromise, generalize, or improve wellbeing.
Choose Tess's next review trigger
Reclassify after the device, account, platform, credential, content, audience, payment method, supporter, security event, or Tess priority changes. Record the qualified owner, current source, effective date, device and account version, ownership and access state, authentication and recovery arrangement, communication, intervention and restriction authority, implementation check, accessible explanation, complaint route, and reassessment date.
Close Tess's personal-technology plan
Review the digital-role boundary register with Tess, the qualified behavior analyst, authorized supporter when applicable, direct team, and specialists named in the manifest. Confirm that emergencies, account and platform decisions, identity, authentication, accessibility, privacy, cybersecurity, communication, assessment, teaching, restrictions, incidents, recovery, and outcomes remain separate; every denominator is reproducible; AAC, authorship, refusal, withdrawal, private content, secrets, funds, and emergency help remain protected; and conclusions stay bounded to sampled conditions. Keep this page draft and noindex until every required review is complete.
Related resources
- How to Triage Account Compromise, Phishing, Identity Theft, Harassment, and Device Loss
- Personal Technology and Digital Communication Support in ABA: A Clinical Playbook
- How to Coordinate an Interdisciplinary Digital-Access and Technology Assessment
- How to Monitor and Reassess an ABA Personal-Technology Support Plan
Sources
- Council of Autism Service Providers, ABA Practice Guidelines Version 3.0 public summary
- Behavior Analyst Certification Board, Ethics Code for Behavior Analysts
- Cybersecurity and Infrastructure Security Agency, Secure Our World
- Federal Trade Commission, How to Recognize and Avoid Phishing Scams
- Federal Trade Commission, IdentityTheft.gov Recovery Steps
- National Institute of Standards and Technology, SP 800-63 Revision 4 Digital Identity Guidelines
- World Wide Web Consortium, Cognitive Accessibility at W3C
- National 911 Program, Calling 911
- U.S. Department of Justice, ADA Requirements: Effective Communication
- American Speech-Language-Hearing Association, Augmentative and Alternative Communication
- Desideri and colleagues, Assistive Technology to Promote Practical Skills in Autistic People and People with Intellectual Disabilities: A Systematic Review