01
Account and domain isolation
Hosted requests resolve through the site and verified domain records. Custom domains must be verified before they can identify a site, and public campaign data remains visibility-filtered.
02
Request integrity
Organization API authentication verifies the signed request and enforces timestamp, nonce, scope and key capability checks. Keep credentials private and use the documented signing process.
03
Operational accountability
Use the existing account permissions, audit information and deployment status when changing sensitive configuration. Investigate payment and access exceptions through the recorded service state.
Connect this to your operating model.
Review your organization or reseller responsibilities alongside the products, account permissions and support arrangements you need.