Skip to content
WHAT WE DO / MANAGED INFRASTRUCTURE · 03 · OPERATE

Security Engineering

Access control, secrets handling and data protection built into the system, not bolted on.

EVIDENCE · ACCESS REVIEW AND AUDIT
Access review · Q312 roles · 3 service identities
Example access review
IdentityRoleScopeLast used
ops@northgateOperatordomains · DNS2 h ago
finance@northgateApproverorders3 d ago
svc-portalServiceread: assetstoday
contractor-04Viewerexpired41 d ago
Reviewed on change and on scheduleRevoke expired
Activity · auditappend-only · newest first
14:02:05 dns.record.updated TXT @ · ops@northgate · change #1204
13:41:22 domain.transfer.requested northgate-holdings.co · awaiting registrar ack
11:08:10 order.approved ORD-0412 · northgate-holdings.io · 1 yr · by finance@northgate
11:07:58 order.quoted ORD-0412 · retail quote issued once
09:30:00 renewal.reminder fundcircle-capital.com · due 21 Sep 2026 · action needed
03:00:12 backup.restore-test records-db · passed · 4 m 12 s
REAL INTERFACE STATES · ILLUSTRATIVE RECORDS
FIG. 07Structure of a delivered system
01 · BUILD02 · CONNECT03 · OPERATESOFTWARE · PLATFORMS · AIINTEGRATION PLANE · APIS · DATA · WORKFLOWScontracts · events · retriesDOMAINS · DNS · CLOUD · MANAGED INFRASTRUCTUREAeltrix NetworkRoles and permissions modelled with the applicationConsequential actions reviewed by a personAccess recordedService identities · least privilegeSecrets never in browsers or business tablesEvery event recordedEncryption in transit and at restChange control on productionDependency and change reviewSECTION A–A · A CLIENT'S SYSTEM IN FULL VERTICAL CUT · EXAMPLE RECORDS
Security boundaries drawn into each layer: identities, secrets, encryption and change control.
WHAT IT CHANGES
  1. 01Control who can access what

    Define clear identities, roles, permissions, and administrator controls across applications and infrastructure.

  2. 02Protect sensitive information

    Use appropriate encryption, secrets management, logging, and data-handling controls.

  3. 03Reduce security risk during change

    Add checks to development, deployment, and operations so security is part of the process rather than an afterthought.

COMMON USES
  1. ·Customer and partner portals

    Accounts, requests, documents and status in one place.

  2. ·Internal administration systems

    Roles, permissions and an audit trail of who did what.

  3. ·Applications handling confidential or regulated data

    Access limited by role; every access recorded.

For technical teams
  • Least-privilege roles and service identities, secrets kept out of code and browsers, encryption in transit and at rest, dependency and change review.
NEXT STEP

Tell us what needs to work better.