Access Map

This document tracks who can access each system, what level of access they have, and how credentials are managed.


👥 Core Access

SystemPrimary OwnerAccess TypeNotes
Zoho OneLuisAdminFull access; tied to corporate email
Microsoft 365LuisGlobal AdminIncludes Outlook, Teams, and OneDrive
QuickBooks OnlineCodyAccountantAccess for financial reports and billing
CloudflareCodyAdminDomain and portal management
Drive (QiVault)CodyOwnerRoot sync + nightly rclone backup
Cursor / GitHubCodyDeveloperFor portal and automation builds

🧱 Access Control

  • MFA required on all admin accounts.
  • Passwords stored in Zoho Vault (shared vault: Operations_Admin).
  • Access reviewed quarterly.
  • Departing users → access revoked within 24 hours.

flowchart TB
  ZOHO["Zoho One"] <--> QBO["QuickBooks"]
  ZOHO --> DRIVE["Drive (QiVault)"]
  QBO --> DRIVE
  DRIVE --> SUPA["Supabase (RAG)"]
  SUPA --> PAGES["Cloudflare Pages"]
  CURSOR["Cursor"] --> GH["GitHub"] --> PAGES
  CF["Cloudflare"] --> PAGES
  CF -. Zero Trust .- ZOHO
  CF -. Zero Trust .- DRIVE


Last updated: 2025-11-12