Trust & access

Production access should be powerful, bounded, and inspectable.

We use the authority the job actually needs, keep consequential changes observable, minimize unnecessary secret exposure, and preserve evidence of what changed and whether it worked.

Access

Prefer task-relevant, least-privilege access and provider-managed authentication. Rotate or revoke standing access when it is no longer needed.

External actions

Queued work, commits, and model claims are not treated as completed external effects. Consequential actions need a real postcondition.

Confidentiality

Private customer material stays private. Sensitive data uses the most appropriate available channel; NDA available when useful.

Security constraints belong in the implementation boundary.

Data locality, credential custody, network boundaries, production access, and change control can change the correct engineering answer.

Security engineering