Tenant and role boundaries
Customer and platform roles are separate. Every sensitive read and write must be authorized against the active organization.
Security and operational control
TopRankPilot treats tenant boundaries, credentials, provider writes, spending authority, verification, and recovery as product behavior.

Customer and platform roles are separate. Every sensitive read and write must be authorized against the active organization.
Provider credentials are encrypted, versioned, refreshable, revocable, and never treated as customer-visible connection flags.
Credits cannot authorize advertising money. Active envelopes and current provider state are checked before execution.
Executions require read-after-write evidence. Retry, reconciliation, pause, rollback, or compensation depends on the action and provider capability.
Your authority stays visible
Start setup now, or inspect the operating loop before connecting a platform.