Security controls · C0128
Is access deny-by-default?
In the pilot (v0.2.0, synthetic data)
Short answer
Yes. Anything not granted by tier or role is denied, and denials return a generic reason while the policy trace is logged.
This exists in the synthetic-data pilot only.
Status as of September 30, 2026. Version 0.2.0, synthetic data only. See what's built today. Not legal, medical or security advice.
Related answers
- How many roles does AuroraMed define? Pilot
- Can a role's title differ from its permissions? Pilot
- Can a manifest grant a low tier a sensitive permission? Pilot
See it in context: Roles and permissions · Search the help center · Ask a question