Access & permissions2 min read
Start public. Grant deliberately.
A proposed staged evaluation policy that keeps documentation access separate from application and financial permissions.
Four stages of access
These are evaluation policy stages, not implemented OAuth scopes or an automatic provisioning service. Exact technical access must be reviewed against the selected deployment.
| Stage | Permitted evaluation | Boundary |
|---|---|---|
| Public reader | Curated documentation and synthetic examples. | No account or record access. |
| Guided demo | Named users, isolated synthetic tenant; read-only first. | Explicit simulation actions only; no privileged shared login. |
| Approved sandbox | Specific organization, operations, assets and test volume. | Time-limited, revocable test access; no production funds. |
| Pilot / live | Separately approved program and reviewed release. | Agreement, acceptance and operational ownership required. |
Define the grant before sharing access.
Record the named users and organization, business purpose, environment, permitted operations, assets/currencies, merchant/provider boundaries, duration, limits, owner, approver and revocation procedure. Verify denied access as carefully as permitted access.
- No source repository, infrastructure console or production access by default.
- No other merchant’s records, customer KYC or raw payment payloads.
- No wallet issuance, payout, FX, refunds or card authority implied by collection access.
- Expire and revoke access through a verified procedure.