Read-only console gallery
Every page of the portal, without live data.
Open each workspace, then each page. This shows layout and role boundaries only. It grants no access and changes no record.
Sahyog PlatformRead only
Sahyog Platform
Prove isolation, freshness and revocation.
Privileged sessions, cross-tenant denials, secrets and break-glass stay visible. Customer files do not.
This page
Always-on controls
Results in the live console. This page explains the checks.
| Control | Question | Pass looks like | Evidence |
|---|---|---|---|
| Tenant isolation | Can one client see another? | Denied by default | Denial log |
| MFA freshness | Is privilege still verified? | Recent authenticator | Step-up record |
| Secret rotation | Are credentials current? | Within policy window | Rotation audit |
| Dependencies | Any critical known issue? | Reviewed and clear | Review note |
On the live page
Work this role can do
1Review a security signal2Revoke a privileged session3Rotate a provider secret4Export audit evidence
Access boundaries
Least privilege by default
- Per-request authorization
- No implicit network trust
- Break-glass needs dual control
Production access
Preview is not permission.
Real consoles appear only after an authorized role, valid scope and required two-step verification are confirmed.