Help and support HLP-012

Account security

Use this guide to protect and recover access and verify the expected product state before moving on. Use this guidance to complete the task safely, understand the result and know where to go when the expected state does not appear.

Bounded, non-exploitative Authorised external assessment.

Bounded evidence. Explicit responsibility. No hidden inference.

The useful answer

Use this guide to protect and recover access and verify the expected product state before moving on.

Use this guide to protect and recover access and verify the expected product state before moving on. Use this guide to protect and recover access and verify the expected product state before moving on. Use this guidance to complete the task safely, understand the result and know where to go when the expected state does not appear.

Route-specific context

The decision this page is designed to support

01
Who should use this
Account user, security administrator
02
Task outcome
Protect and recover access. Use this guide to protect and recover access and verify the expected product state before moving on.
03
Safe checkpoint
Tenant isolation, delegated access, AAL2 controls and bounded signed downloads protect customer evidence. Evidence basis: RLS, delegation and cross-tenant tests.

A deliberate path

From permission to retained evidence

  1. 01

    Enable MFA and use a current authenticated session before opening report evidence.

  2. 02

    Review team membership, active sessions and scoped integrations from Settings.

  3. 03

    Revoke unexpected access promptly and use responsible disclosure for a suspected platform vulnerability rather than a support form.

Evidence before assertion

What the product can support

The interface reports real operation states. Do not repeat a submission while a job is active; use the shown recovery action or contact support with the non-sensitive reference displayed on screen. Tenant isolation, delegated access, AAL2 controls and bounded signed downloads protect customer evidence.

Qualified statement

Portfolio and MSP workflows separate tenants, domains, responsibility and delegated access.

RLS, delegation and cross-tenant tests

Direct answers

Questions a careful reader should ask

What does Account security establish?

Use this guide to protect and recover access and verify the expected product state before moving on. It establishes only what the governed evidence supports.

What does it not establish?

It does not prove complete organisational security, exploitability, breach likelihood or the absence of unobserved weaknesses.

How can I verify the conclusion?

Use the linked evidence or capability record to inspect source, observation time, target, responsibility and the condition required for closure.