Skip to content

Security guidance

Security guidance

Use least privilege, tenant-safe roles, verified callbacks, protected credentials and explicit human authority.

These guides describe the documented product workflow. Confirm the visible role, connection and permission state in the App before live use.

02 · Safe sequence

No certification, compliance status, uptime or incident-free claim is implied by these engineering controls.

  1. 1

    Use a unique account and complete the configured verification flow; never share a session or provider credential.

  2. 2

    Confirm workspace and role before every export, connection or settings change.

  3. 3

    When reporting an issue, include route, time and safe visible state—not message content, tokens or personal data.

  4. 4

    For suspected compromise, stop live actions, sign out and use only the verified recovery/contact route when published.

03 · Expected result

Expected result

For suspected compromise, stop live actions, sign out and use only the verified recovery/contact route when published.

Use least privilege, tenant-safe roles, verified callbacks, protected credentials and explicit human authority.

04 · If the expected state does not appear

If the expected state does not appear

Stop before repeating a provider or mutation action. Record route, time and safe visible state—never message content, tokens or customer data.

Troubleshooting

Reviewed 24 August 2026