This starter has no authentication. Build your private copy and verify access before adding org information.
Access & hosting
| Resource / action | Who or which agent can read | Who can edit or propose within scope | Approval required when / by whom | Actual control | Verification result |
|---|---|---|---|---|---|
| [resource] | [scope] | [scope] | [owner] | [tool ACL, credential scope, branch rule, etc.] | [untested / evidence] |
Private repos still require appropriate membership. Repository folders do not isolate reads. Separate restricted client and personal context. CODEOWNERS review routing requires enforced branch/ruleset review to block unauthorized changes; check bypass permissions.
Use harmless dummy material for permission tests. Do not copy real secrets into test prompts. Check delegated tools and search indexes, not just direct file access.
Hosting and identity
- Canonical internal URL / workspace: [destination]
- Host or knowledge-base service: [name and plan]
- Identity provider / SSO configuration: [actual setup or unavailable]
- Allowed people and groups: [scope and owner]
- Restricted areas and separate boundaries: [resources and controls]
- Edit / review / publish route: [people and controls]
- Agent access method: [authorized connector, scoped identity, browser, or checkout]
- Preview / origin / alternate URLs: [protection and bypass checks]
- Downloads, search indexes, and exports: [same effective audience or separately restricted]
- Offboarding and access review owner: [name, cadence, and revocation test]
A private repo, an unlisted URL, noindex, or a hidden menu is not protection for a deployed site. This starter has no built-in authentication. Follow the setup guide before using real org data.
Access verification
| Test identity / route | Expected access | Actual result | Evidence / date | Gap owner | | — | — | — | — | — | | Intended staff member: direct page + download | Allowed | Untested | [record] | [name] | | Signed out: direct page + download | Denied | Untested | [record] | [name] | | Signed in outside intended group | Denied | Untested | [record] | [name] | | Colleague outside a restricted area | Denied there | Untested | [record] | [name] | | Authorized agent and delegated tools | Scoped access only | Untested | [record] | [name] | | Removed user, preview and origin routes | No unintended access | Untested | [record] | [name] |
Use harmless dummy content. Mark unavailable checks unverified. Link to the relevant platform’s current permissions documentation and record actual configured controls, not assumptions.
Before external action
[Specify exactly who may send, publish, change permissions, or spend money, under what authorization. Draft completion is not approval to act.]