Security overview
The Crusoe Agent Platform identity model — two axes of authority, the roles table, the 404-vs-403 rule, and why platform staff cannot read your data.
API authentication
The four credential shapes the platform accepts, the Bearer header, 12-hour session tokens, rate limits, and live permission re-resolution.
Break-glass and audit
How platform staff get temporary, visible, audited access to a project — and what the per-project audit log records and guarantees.