Access
Access is limited to what the agreed workflow requires. Client-owned accounts and least-privilege roles are preferred where the platform supports them. Credentials should be shared through an approved credential manager, never ordinary email or chat.
Human approval
Legal, financial, customer-facing, destructive, or otherwise sensitive actions require explicit approval boundaries. Automation does not replace professional judgment or accountability.
Testing and failure handling
Build scopes define expected inputs, exceptions, retries, duplicate handling, alerts, logs, and a manual recovery path. Acceptance criteria are agreed before production launch.
Data and retention
Data collection and retention depend on the workflow and vendors involved. The engagement should identify systems of record, permitted data, retention, deletion, logs, and offboarding. Sensitive data should not be copied into AI systems unless that use is explicitly reviewed and approved.
Ownership and offboarding
Documentation, account ownership, credentials, vendor dependencies, monitoring, and removal of SuncoastOps access are included in handoff or offboarding planning.
Questions or incidents
Use the contact form for security questions. Do not include passwords, secret keys, confidential client records, or sensitive personal data in the form or AI receptionist.