Security & access
Documentation ยท 1.0
High-level control principles for SAS configuration and data movement.
SAS connects systems, data, and processes. Configuration therefore needs clear ownership, controlled access, and traceable operational handling.
Control principles
- Grant users access according to their role.
- Keep environment-specific credentials separate from reusable integration logic.
- Use shared naming and folder conventions.
- Review API methods, write modes, key fields, and destructive actions before publication.
- Document assumptions and maintenance information in Notes.
- Agree who edits shared configuration because last change wins.
- Rotate credentials and API keys before expiry.
- Use run results and Messages to investigate failures before changing configuration.
Data movement
The component documentation makes the main data path visible:
- API Composer records the source, request, and output mappings.
- Dataflow Composer shows sources, links, transformations, filters, and output fields.
- Endpoint Composer shows the published object, allowed methods, key fields, and security profile.
This page is an operational overview. Formal security, compliance, and audit claims remain subject to the current SAS security documentation, agreements, and review process. See Data security & data control for the wider platform direction.
View the current version in the wiki