Role-based controls
Owner, admin, editor, viewer, billing, support, and operator paths are separated so privileged actions stay intentional.
Preparing PyroSync...
Loading the command surface and keeping your workspace state intact.
Security
PyroSync treats access control, credential boundaries, tenant scoping, and launch evidence as product surfaces, not afterthoughts.
workspace/default
RBAC and operator gates
ready
Control plane
scheduled
Worker fleet
bounded
posture
Customer workspaces are separated from operator-only paths with RBAC, privileged API-key controls, audited support workflows, and launch evidence before production promotion.
Owner, admin, editor, viewer, billing, support, and operator paths are separated so privileged actions stay intentional.
API keys, integration credentials, and tenant database bindings are handled as secrets and never exposed in customer UI.
Production promotion depends on health, migration, smoke, benchmark, and route evidence agreeing.
Operator, infrastructure, and destructive paths require privileged roles and explicit action boundaries.
Workspace identifiers, provisioning states, and migration checks keep customer data operations traceable.
Support impersonation is designed around actor metadata, target-user scope, visible return state, and auditability.
Preview and worker flows are guarded against private-network targets, unsafe redirects, and active-content preview risks.
Start with a safe workspace, prove the workflow, then promote to managed production capacity when migrations, tenant data, and authenticated smoke evidence are green.
Start Building