OPERATING STANDARD · ACCEPTABLE USE

Use control authority only for an assigned and reviewable purpose.

This standard governs identity use, resource access, data handling, automation, security testing, prohibited behavior, reporting, and enforcement.

Owner
Security Assurance
Version
1.3
Effective
05 Aug 2026
Applies to
All assigned identities

1. Authorized use

Use is limited to the assigned identity, current role, approved resource scope, and legitimate operating, assurance, or support purpose. Users must verify the production environment and change authority before a mutation. Shared accounts, shared sessions, and transferred MFA values are prohibited.

2. Required behavior

  • Use the canonical HTTPS origin and protect authentication material.
  • Apply least privilege and the smallest effective operational change.
  • Record change, resource, request ID, result, and rollback evidence.
  • Report suspected unauthorized access, credential exposure, or control failure promptly.
  • Remove exported records and temporary working copies when their task ends.

3. Prohibited behavior

CategoryExamples
Access abuseBypassing role controls, impersonation, session sharing, or using another identity
Service harmTraffic flooding, destructive mutation, resource exhaustion, or unauthorized persistence
Data misuseAccessing, exporting, disclosing, or retaining data outside assigned purpose
Secret handlingPublishing or storing passwords, factors, cookies, private keys, or tokens in unapproved locations
Control evasionDisabling audit, falsifying evidence, bypassing approval, or concealing material errors
External claimsPresenting integration labels as certification, endorsement, ownership, or provider affiliation

4. Automation and API clients

Automation must use an approved identity and documented purpose, respect rate controls, send valid content types, retain request IDs, stop on deterministic authorization or validation failure, and avoid unbounded retries. Browser session cookies are not general integration credentials.

5. Security testing

Testing outside ordinary operation follows the Vulnerability Disclosure Policy or specific written authorization. Denial-of-service testing, credential stuffing, social engineering, persistence, destructive testing, and access to data outside the testing identity are not authorized by normal account access.

6. Enforcement and reporting

Controls may rate-limit requests, reject mutations, revoke sessions, suspend an identity, preserve relevant audit evidence, and require review. Enforcement should be proportional to verified risk and documented. Suspected violations enter the incident or access-review process; reporters should preserve request IDs without copying active secrets.