Local production controls

Security & Reports

Authenticated asloading
Roleloading
Auth methodloading
Rate limit0/min
Active sessions0

Session Controls

Request IDnone
Expirestoken
Lockout0m
Failures0

Protected Exports

Session Policy

Operational routes require a local token or expiring session.
API tokens are matched by hash and denied with constant-time comparison.
Repeated failed auth attempts create security events and short lockouts.

Token Rotation Plan

ActorRoleNew fingerprint

Active Sessions

admin
ActorRoleFingerprintExpires

Security Events

admin
TimeTypeActorFingerprint

Rate Limit Buckets

admin
ActorRequestsResets

Audit Trail

analyst
TimeActorActionEntity