SigID Dashboard Terms
# SigID Dashboard Terms
SigID Dashboard is for authorized organization owners and tenant operators. Access to a page or control does not itself grant authority: the server enforces tenant membership, roles, scopes, policy, fresh authentication, billing entitlements, and audit requirements. Operators must configure only organizations, applications, users, identity providers, webhooks, policies, commerce settings, and billing resources they are authorized to administer, and must preserve least privilege when assigning access.
Automation should use the documented API, OAuth metadata, OpenAPI schema, SDKs, or SigID CLI instead of scripting the Dashboard. API clients must validate responses, preserve idempotency keys on retryable writes, respect `Retry-After`, keep credentials out of logs and prompts, and avoid depending on internal control-plane routes that are not in the public OpenAPI document. Security research must not impair production or access another tenant's records.
Commercial terms, service levels, data-processing terms, and deployment responsibilities depend on the governing customer agreement. Product questions go to `sales@sigid.org`, legal questions to `legal@sigid.com`, privacy requests to `privacy@sigid.com`, and responsible security reports to `security@sigid.com`. This summary does not expand an operator's tenant authority or the published API contract.