Security / access boundaries

ACCESS
WITH PURPOSE.

Security is part of scope. The right access is the smallest access needed to perform the written work, with ownership and revocation remaining visible.

01 / AccessLeast privilege

Use role-based, collaborator, staff or temporary access whenever the platform supports it. Access is requested after scope is clear.

02 / CredentialsNo raw passwords

Do not email or paste passwords into standard forms. Use platform-native invitations, password managers or another agreed secure handoff.

03 / DataMinimum necessary

Share the data and environments needed for the purchased work. Sensitive or regulated data must be disclosed before implementation and may require a different design or a decline.

04 / ChangeDocumented production work

Production changes should have a defined owner, scope, verification path and rollback or recovery consideration appropriate to the system.

05 / CloseoutRevoke and hand off

Temporary access can be revoked after delivery. Documentation should identify what changed, what remains, and who owns the next action.

06 / BoundaryNot a blanket certification

This public page describes operating practices, not a SOC 2, ISO 27001, penetration-test or legal compliance certification. Specific requirements belong in the written scope.