Settings: Security
Security on a tenant is mostly discipline, not knobs: the right people, the smallest roles, healthy sign-in, and attention to the approval record. This page is the checklist version of that discipline.
Scope note: this page covers tenant-level security hygiene at a high level. Platform-level internals (identity provider wiring, provisioning flags) belong to Platform ops and are not documented here. If a control you expect is not visible in your tenant UI, ask the PRESHai team rather than assuming it exists.
Sign-in hygiene: checklist
Section titled “Sign-in hygiene: checklist”- Every person uses their own named identity. No shared accounts, ever.
- Access changes on role change or departure go through offboarding promptly
- Invite links are shared directly with the intended person, not posted in group channels
- Anyone reporting sign-in trouble gets help quickly. Slow account recovery drives password-sharing workarounds.
Least privilege: checklist
Section titled “Least privilege: checklist”- Admins at 3 or fewer with absence coverage (Roles)
- Operators earned solo approval rights by pairing first
- Members see only the environments their work needs
- Quarterly membership review is scheduled and happens
Session and approval hygiene: checklist
Section titled “Session and approval hygiene: checklist”- Operators decide approvals at request time, not in batches
- Denials exist in the record (zero denials means rubber-stamping, so investigate)
- Sensitive departures trigger a review of recent sessions and approvals
- Session goals stay single and scoped; sprawling sessions get ended and restarted
What to watch
Section titled “What to watch”| Signal | Meaning | Action |
|---|---|---|
| Approval with no clear what/on-what/why | Agent or environment issue | Deny; report with session reference |
| Risky work with no approval gates | Policy too loose | Stop, report to PRESHai team immediately |
| Routine work constantly gated | Policy too tight | Collect examples, request tuning |
| Unfamiliar identity in member list | Stale or wrong grant | Verify, remove if unneeded |
| User “cannot reach a system” | Connector not provisioned for the environment | Verify tool list; request provisioning. Code is not connected. |
Incident posture
Section titled “Incident posture”If you suspect misuse or a compromised identity:
- Remove or demote the identity first. Contain, then investigate.
- Preserve the record: note tenant hostname, org scope, session references, timestamps.
- Contact the PRESHai team with that evidence pack.
- Review and tighten: how did the access exist, and what prevents recurrence?

