An administrator cannot grant themselves the intelligence content.
Local identity, bounded access changes and audited grants with no content bypass.
How it works
Local identity uses AIC.Foundation and AIC.Foundry. Initial provisioning is explicit, there is no shared default password, and routine startup does not create users or reset credentials. Self-service profile editing updates names only.
Boundaries
Administrative permission supplies no intelligence-content bypass and cannot be used to edit one’s own grants. Workspace membership remains a separate decision.
Identity and administration
Element
Platform & access
Versioning
Finite expiry
Human decision
Audited decision
Status
Implemented