SAG / ANSWER CENTER
Should API keys be included in materials?
Keep keys and passwords out of materials and public documents; use approved secret configuration channels.
Method and interpretation
Public FAQs explain general capabilities; tenant workspaces contain authorized company records. Check sharing rights, personal data and secrets before registration. External-service credentials and permissions to view tenant records are distinct access scopes.
How to use it
SAG technical notes (Korean)
- RBAC and Tenant Boundaries: Completing Authorization Checks Beyond the UI
- Customer Data Cache Lifetime: Preserving Speed and Logout Boundaries
