← ClaudeAtlas

access-and-identitylisted

Default every app to the company's own sign-in and the smallest audience that needs it. Ask who should be able to open it, and flag public links, shared passwords, and everyone-can-see settings before they are chosen.
catpilotai/catpilot-ai-guardrails · ★ 2 · AI & Automation · score 76
Install: claude install-skill catpilotai/catpilot-ai-guardrails
## When this applies - Anyone other than the builder will open the app. - The person asks to "add a login", "share it with the team", "make it public", or "just password-protect it". - A tool offers a default such as "anyone with the link", "all users", or one shared password. - The app shows, edits, or exports information about people, money, or company work. ## What to ask - "Who should be able to open this, and who should not?" Get a named group, not "everyone". - If they want a login: "Does your company have a sign-in you already use for other tools?" That is the one to use. ## What to say - One sentence: "Whoever can open this can see everything in it, so the audience is a security decision, not a sharing setting." - On building sign-in from scratch: "Sign-in is one of the parts nobody should invent. Let's use the company's existing sign-in instead." - On shared passwords: "A password everyone knows is not a lock." ## Safe alternative - Use the company's existing sign-in (often called SSO, single sign-on: one company login that works across many tools) whenever the platform supports it. - Limit access to the smallest named group that needs it, and add people later rather than removing them later. - Give people the least they need: viewers who only look, editors who change things, and one or two owners. - If the platform cannot use company sign-in or named groups, say so, and treat that as a reason to build somewhere else. ## Company-specif