A verified organisation with named administrators, separated environments, and credentials stored by an accountable owner.
Create and verify the organisation
Use a work email address controlled by the organisation. Record the organisation name, the first product or project, and the person accountable for access decisions.
- 01Create the organisation account and verify the work email address.
- 02Confirm the organisation and project names used by the delivery team.
- 03Add a second administrator so access is not dependent on one person.
- 04Record the support and escalation contact for the project.
Assign access by responsibility
Give people only the access required for their work. Product, engineering, service, customer support, and external partners should not automatically receive the same permissions.
- Organisation administrator: manages users, environments, and policy.
- Device administrator: provisions devices and rotates device credentials.
- Builder: configures variables, dashboards, events, and reports.
- Operator or viewer: monitors assets and follows approved actions.
Protect tokens and environment boundaries
The authenticated portal or onboarding record provides the credential and base URL assigned to the deployment. Treat every token like a production password.
- 01Keep development and production credentials separate.
- 02Store server and device secrets in an approved secret manager or secure provisioning flow.
- 03Never paste credentials into source repositories, screenshots, or support tickets.
- 04Record the owner, purpose, issue date, and rotation trigger for each credential.
Rotate a credential immediately when its owner changes, a device is transferred, or exposure is suspected.