Security model
- authenticate users through the platform’s session and token contracts;
- keep authorization checks on the server;
- scope project operations to the workspace and project;
- use roles and permissions for project-specific access;
- never put provider or deployment credentials in generated browser code.

