ARVICA / DOCUMENTATION
Teams and account security
Keep access aligned with each person’s role.
Company-scoped access
Workspace data and customer API responses are restricted to the signed-in company. Administrator actions require the appropriate role; access to one company does not grant access to another company’s resources.
Key hygiene
Use separate API keys for separate integrations, choose the minimum scope and set an expiry. Revoke keys when no longer needed. Keep private SSH keys and API tokens out of tickets, screenshots and source repositories.
Account review
Review active team membership regularly. API access depends on the issuing user’s current access and key status. A leaked credential should be revoked promptly; send support the resource reference, never the secret.