Operating policy

Security Practices Overview

Delegated work should use least privilege, explicit approval, access records, and revocation planning before any assistant or workflow receives client-system access.

Access model

Use named accounts where possible, password managers, limited permissions, client-approved access, and separate approval for privileged actions.

Operational controls

SOPs, QA sampling, activity notes, escalation rules, and evidence of completed work help clients review outcomes and recover from mistakes.

Incident handling

Suspected misuse, credential exposure, data mishandling, or unsafe access should be escalated to the client owner and GlobalAdmin.ai contact immediately.