Deny by default
Identity status, account assignment, exact module entitlement, permission, record scope, and security conditions are evaluated on the server.
Company isolation
Tenant and site identifiers are derived from the authenticated account. Browser-supplied overrides are rejected.
Protected providers
Credentials remain encrypted and write-only. A saved credential is not reported as a healthy connection until the provider confirms it.
Audited changes
Administrative and sensitive actions retain actor, target, scope, decision, time, and correlation evidence without storing passwords or tokens.