Access Flow
Request Submitted
Send the complete request to help@axiom.express.
Review Pending
The request is checked for environment, custody, support, and intended use.
Approved
Approval names the access lane, permitted first read, expiry or review date, and exclusions.
Access Pack Issued
Credentials and tenant selection instructions are issued only through the approved private channel.
Smoke Verified
Access becomes active only after redacted smoke evidence proves auth, tenant discovery, tenant context, and one first read.
Request Fields
Include every field below. Leave secrets, bearer tokens, tenant-context tokens, tenant-owned business data, private tenant identifiers, and screenshots containing credentials out of the request.
| Section | Required fields |
|---|---|
| Requester | Requester name, requester email, organisation, support contact, preferred private delivery channel. |
| Intended use | Application name, target environment, access lane, intended first integration journey, resource families required, backend boundary owner, expected first-read route. |
| Data and custody | Real tenant-owned business data statement, data classification summary, secrets storage owner, token handling boundary, browser/client exposure risk review. |
Copy Request Template
Requester name:
Requester email:
Organisation:
Support contact:
Preferred private delivery channel:
Application name:
Target environment: afr-dev
Access lane: human login | machine/client credentials | both
Intended first integration journey:
Resource families required:
Backend boundary owner:
Expected first-read route:
Will real tenant-owned business data be used during alpha? yes | no
Data classification summary:
Secrets storage owner:
Token handling boundary:
Browser/client exposure risk reviewed? yes | no
Alpha Boundary
afr-dev
human | machine | both
private channel only
server-minted
Request access does not create credentials automatically during alpha or beta. It starts the governed beta sandbox access path: request intake, triage, operator approval, sandbox provisioning, private access-pack issue, redacted smoke proof, and activation.
Browser applications must not hold confidential Axiom credentials, bearer tokens, or tenant-context tokens. Keep credential exchange, token refresh, and tenant-context handling behind the backend boundary named in the request.
Support
Escalate without leaking secrets
For failed calls after access is issued, send endpoint path, method,
UTC timestamp, HTTP status, X-Correlation-ID, contract
version, SDK lane if used, and sanitized request or response shape.