Policy & trust

Account Access & Security

Prinil’s public account-access standard covering least privilege, prohibited credentials, MFA, approvals, retention review, and offboarding.

Prinil requests only the access needed for agreed work, uses role-based or delegated access where supported, and documents removal at handoff.

Project-specific permissions and security responsibilities are confirmed in writing before access is requested.

Least privilege

Design and research work usually require no store access. Publishing or operations work should use the narrowest current role, staff, collaborator, or delegated route that supports the approved tasks.

Credentials Prinil does not request publicly

  • Passwords.
  • Backup or recovery codes.
  • Payment credentials.
  • Tax or identity records.
  • Private customer or account exports.

MFA and approvals

The account owner retains control, approves sensitive actions and spend, and uses the platform’s current secure invitation route. MFA responsibilities and any temporary access should be documented.

Storage, incidents, and offboarding

The project record identifies the approved tools, storage, retention review, incident escalation, access review, and removal procedure. At handoff, current records are returned and access no longer needed is removed.