11
Access reference
Security model
- Authentication and role checks run on the server; the browser does not decide access.
- Login attempts are rate-limited and credentials are not written to audit details.
- Administrator manages applications and Home content.
- User administration additionally requires time-limited Superadmin elevation.
- Embedded and code applications run in sandboxed frames with restricted capabilities.
- Administrative changes produce sanitized audit events.