Skip to content

Settings: Security

Security on a tenant is mostly discipline, not knobs: the right people, the smallest roles, healthy sign-in, and attention to the approval record. This page is the checklist version of that discipline.

Scope note: this page covers tenant-level security hygiene at a high level. Platform-level internals (identity provider wiring, provisioning flags) belong to Platform ops and are not documented here. If a control you expect is not visible in your tenant UI, ask the PRESHai team rather than assuming it exists.

  • Every person uses their own named identity. No shared accounts, ever.
  • Access changes on role change or departure go through offboarding promptly
  • Invite links are shared directly with the intended person, not posted in group channels
  • Anyone reporting sign-in trouble gets help quickly. Slow account recovery drives password-sharing workarounds.
  • Admins at 3 or fewer with absence coverage (Roles)
  • Operators earned solo approval rights by pairing first
  • Members see only the environments their work needs
  • Quarterly membership review is scheduled and happens
  • Operators decide approvals at request time, not in batches
  • Denials exist in the record (zero denials means rubber-stamping, so investigate)
  • Sensitive departures trigger a review of recent sessions and approvals
  • Session goals stay single and scoped; sprawling sessions get ended and restarted
Signal Meaning Action
Approval with no clear what/on-what/why Agent or environment issue Deny; report with session reference
Risky work with no approval gates Policy too loose Stop, report to PRESHai team immediately
Routine work constantly gated Policy too tight Collect examples, request tuning
Unfamiliar identity in member list Stale or wrong grant Verify, remove if unneeded
User “cannot reach a system” Connector not provisioned for the environment Verify tool list; request provisioning. Code is not connected.

If you suspect misuse or a compromised identity:

  1. Remove or demote the identity first. Contain, then investigate.
  2. Preserve the record: note tenant hostname, org scope, session references, timestamps.
  3. Contact the PRESHai team with that evidence pack.
  4. Review and tighten: how did the access exist, and what prevents recurrence?