← Back to Documentation
Deploy & Configure
Security Settings
Harden your deployment with identity, key rotation, provider, and audit controls.
Key Steps
- Use least-privilege admin access and rotate provider credentials on a schedule.
- Keep deployment secrets private and monitor license validation failures.
- Review user access, quotas, and provider availability before broad rollout.
Article Scope
This guide focuses on the operational steps needed to run Orchestris with team access, provider control, and predictable usage.
Visual Reference
Baseline controls
- Limit portal admin access to the people who operate billing, users, and deployments.
- Use unique provider keys for the Orchestris workspace instead of sharing personal keys.
- Keep TLS enabled for every client-facing endpoint.
Credential rotation
- Rotate provider keys when team ownership changes.
- Rotate deployment secrets when a server image, log, or ticket may have exposed them.
- Retire old credentials after confirming replacement traffic is healthy.
Access review
- Review admins, inactive users, and high-quota users regularly.
- Confirm model access matches your internal data policy.
- Use support logs and usage reports to investigate unusual patterns.