Security

Administrator Access Policy

Privileged-access authorization, purpose limitation and audit rules

Certifiedge Internally Approved — Deployment Activation PendingPublic activation is intentionally blocked until verified operator/provider details are configured.

Least privilege

Administrative access is capability-, tenant-, relationship- and purpose-bound. Being logged in is never sufficient authority.

Separation of duties

Where the system defines reviewer, validation and release roles separately, privileged users must not collapse those duties merely for convenience.

Sensitive access

Access to child, assessment, evidence, finance, AI or incident records is limited to the minimum needed for the task.

Audit

Consequential administrative mutations and sensitive access should be attributable to an actor, resource, time and result.

Emergency access

Break-glass access, if used, requires justification, time limitation and post-event review.

Questions or requests

Use the Certifiedge contact, complaints or data-rights route appropriate to the issue. Internal policies do not remove rights or remedies available under applicable law.