Identity and administration

An administrator cannot grant themselves the intelligence content.

Local identity, bounded access changes and audited grants with no content bypass.

How it works

Local identity uses AIC.Foundation and AIC.Foundry. Initial provisioning is explicit, there is no shared default password, and routine startup does not create users or reset credentials. Self-service profile editing updates names only.

Boundaries

Administrative permission supplies no intelligence-content bypass and cannot be used to edit one’s own grants. Workspace membership remains a separate decision.

Identity and administration

Element

Platform & access

Versioning

Finite expiry

Human decision

Audited decision

Status

Implemented

Related capabilities