DOCUMENTACIÓN
Security and credentials
Review identity, RBAC, secrets, audit, network, backup, and responsibility boundaries.
Identity and authorization
Define the identity source, workspace membership, role mapping, least privilege, privileged access review, and service account lifecycle. Treat upstream SSO as an integration to validate.
Data and secrets
Keep data-source credentials, tokens, encryption keys, and production data in the customer-controlled boundary. Restrict logs and exports that may carry sensitive fields.
Audit and assurance
Identify actions that require evidence, retention, alerting, and periodic review. Certification, compliance, penetration testing, and SLA terms are evidenced and agreed separately when required.
This guide consolidates repository README files, deployment notes, security guidance, and anonymized engineering records. Validate environment-specific decisions during architecture review.
Open source repositories