Least privilege, deny by default
Access is granted by explicit intersection, not inherited by seniority or role name.
Identity and access, encryption in transit and at rest, environment and tenant boundaries, change control, monitoring, incident response, evidence, human authority, and a clearly stated split of responsibility between ZoikoTime, your organization, and your providers.
.png)
Security telemetry covers approved identity, access, change, source-health, service, and incident events. It does not cover what a person types, reads, visits, or copies. Security logs are operational records — they are not worker-behavior scoring, and no administrator setting turns them into one.
Principles are not certifications. They describe how the controls below are designed — nothing more.
Access is granted by explicit intersection, not inherited by seniority or role name.
Collect and retain only what the stated purpose requires. Restricted data stays out of ordinary logs and analytics.
Tenant, entity, object, source, and action scope are stated rather than assumed.
Consequential review stays with authorized people. Automation assists; it does not conclude.
Changes carry versions and evidence. Corrections are recorded, not overwritten.
Defaults are safe, and what your administrators can change is visible to them.
Effective access is a deny-by-default intersection of role, tenant, entity, object, source, policy, and action. One role never grants unrestricted data access.
Application-name monitoring, URL history, or keystroke content. Sensitive payloads and the prohibited surveillance categories are excluded from logs by design, not by configuration.
Provider controls are provider controls. We do not present them as ZoikoTime controls, and we do not inherit assurance from a vendor's certifications.
Provider record— purpose, data categories, access, region, and contractual control.
Connector scopes— credentials, revocation, and rotation ownership stated explicitly.
Transport integrity— webhook, file, and API authenticity, replay handling, and failure behavior.
Visible limitations— provider state and constraints stay visible rather than abstracted away.
If a connected system is compromised, the blast radius is bounded by the scope you granted it — which is why connector scope, credential ownership, and revocation authority are worth reviewing before you enable one.
A failed integration never broadens access to complete an exchange. Failure states stay visible and owned.
Objective, scope, mechanism summary, dependencies, and limitations.
Classification, minimization, transport and storage protection at public-safe level.
Release gates, approval records, and rollback evidence at review depth.
Event categories, purpose, retention, access, and exclusions.
Restoration test scope, frequency, and outcome at review depth.
Assessment summaries where current, with issuer, exact scope, and period.
Withdrawn and superseded evidence is not presented as current. Restricted artifact titles are withheld where their existence is itself sensitive, and search terms are never captured in analytics.
Shared responsibility describes where duties genuinely sit. It is not a mechanism for moving platform obligations onto you.
Enable prohibited surveillance. The anti-surveillance invariant is not a default, a setting, or a permission — there is no administrative path to screenshots, keystroke content, URL history, application-name monitoring, or clipboard collection.
Access level is determined by identity, purpose, and entitlement. Minimal fields, optional free text, secure delivery with expiry.