What applies without configuration
- Everything denied: A new account has exactly one authorised person — the account owner. Every additional person and every service account starts with no permissions. There is no role that is automatically included upon creation.
- Denial beats permission: If multiple policies apply to the same request, the denial wins — regardless of the order and specificity of the rule.
- No inheritance across project boundaries: Permissions in one project say nothing about another. Anyone who needs to work across projects needs a role per project or a role at the account level.
- Two factors for write roles: Administrator, operator and security officer can only be assigned to people who have set up a second factor. TOTP (one-time codes from an authenticator app) and WebAuthn (security keys or device biometrics) are permitted; recovery codes are provided once during setup.
- Service accounts without an expiry date do not exist: An access token lives for one hour, a key pair for a maximum of 90 days. From day 60, a warning appears in the account and in the API response as a header.
- The audit trail cannot be disabled: Even the account owner cannot turn it off, shorten it, or delete entries. This is intentional and the condition for it to serve as evidence.
Default values of a new account




