Explainer
What is an access mandate?
An access mandate (Technical Access Mandate) is the boundary your organisation approves for what STRIA may do in your systems: which systems, which environments and until when. STRIA works only inside that boundary and asks you when something falls outside it. An administrator can change or revoke the mandate at any time under Access.
To fix or build something in your own systems, such as a code repository, a hosting platform or a database, STRIA needs access to them. The mandate makes that access explicit. You approve a boundary once instead of answering questions about every single action, and STRIA asks only when something falls outside it.
What a mandate contains
| Item | What it means |
|---|---|
| Mode | How much STRIA may do, see the modes below |
| Systems | The systems the mandate covers, for example a code repository |
| Environments | Development, Test, Staging and in some cases Production |
| Until | An end date, or Until you change or revoke it |
| STRIA can and STRIA cannot | What the mode allows and explicitly does not allow |
| Always a separate approval | Actions that always need your approval, whatever the mode |
| Approved by and Version | Who approved it and which version applies |
The three modes
| Mode | What it means |
|---|---|
| Managed Development Access | STRIA works independently in development and test environments. Production is not touched. |
| Managed Production Access | STRIA may also deploy approved low-risk releases according to your production policy. Destructive changes always need a separate approval. |
| Restricted Access | STRIA gets only what you selected. Everything else, STRIA asks you about, every time. |
Production
Production can only be part of Managed Production Access. Production access means approved low-risk releases under your production policy. It never means destructive database changes, unrestricted infrastructure changes or bypassing risk and approval.
Always a separate approval
Some actions always need a separate approval, whatever the mode. Examples are destructive data operations, schema changes in production and critical infrastructure or security changes. They are listed under Always a separate approval in the mandate.
When STRIA needs more
STRIA then sends an access request before taking the action. The request shows what STRIA asks for, why, which system, which environment, for how long, the risk and what happens if you decline. An approved request covers only what was asked, only there and only for the stated time. It does not change your access boundary.
Who decides?
Only the organisation's administrators see Access and can approve, change or revoke. Members and Billing never decide on access. Whoever requests access can never approve it themselves, and STRIA cannot approve an expansion of your boundary on your behalf.
No passwords in the mandate
The mandate never contains passwords or other secrets. It describes what STRIA may do. Credentials are handled separately and encrypted.