Access and audit
Apply roles, attributes, key scopes, policies, and approvals at the point where work is performed.
People use roles and attributes. Applications use scoped keys. Policies decide whether a requested action is allowed in its current context. Approvals introduce a deliberate human decision when risk warrants one.
Record security-relevant events—access changes, key creation and rotation, policy decisions, approvals, and actions—in an append-only audit trail. An audit record should identify the actor, target, decision, time, and correlation identifiers needed to connect it to a run.
Actualizado el 31 ago 2026