Data access and impact levels
We classify information assets, assess associated risks, and apply controls proportional to their impact. Access follows least privilege and role-based access control (RBAC), as described in Security Measures.
A documented mapping of data-access and impact levels is still being formalized. Until it is published, resources stay focused on protecting the most sensitive information while keeping the Service operable.