People and access
Use named human accounts for everyday work. Reserve the installation Owner token for recovery.
Built-in responsibilities
- A Member uses the normal document workflow.
- An Administrator manages the installation and household configuration but does not implicitly see every restricted document.
- The installation Owner retains a durable recovery grant.
Groups and custom permission sets can model recurring needs without granting every person broad administration rights.
Restrict exceptional documents
The household library is shared by default. A document manager can restrict a sensitive document to named people or groups and grant Viewer, Editor, or Manager access. Use restrictions for exceptions rather than building a maze of one-off rules.
After changing access, verify with a real test account. An administrator view alone cannot prove what a Member sees.
Sessions and tokens
Revoke sessions when a device is lost or an account changes hands. Personal access tokens should be scoped, expire, and belong to a named integration. Their raw value is shown only when created, so place it directly into the integration's secret store.
Review periodically:
- inactive human accounts;
- administrators who no longer need the role;
- unused or non-expiring personal access tokens;
- external identities linked to each account;
- restricted documents whose access list no longer matches reality.