First-party accounts and explicit scope
Protected actions use server-side sessions and authorization. Organization roles, direct project grants, session controls, and administrative audit events define who may reach each workspace surface.
Review platform security