> For the complete documentation index, see [llms.txt](https://help.transform.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.transform.ai/account-and-billing/security-and-compliance.md).

# Security & Compliance

### Overview

Security and compliance covers controls that reduce risk in Transform.

Think access control, auditability, and safe operational practices.

### Key Concepts

* **RBAC**: role-based access control
* **Audit trail**: history of changes and who made them
* **Least privilege**: grant the minimum access needed

### How It’s Used

Use these controls during rollout and ongoing governance.

Use them during audits, investigations, and access reviews.

### Benefits

* Reduced risk from over-scoped access
* Stronger evidence for approvals and scope changes
* Faster investigations through consistent audit signals

### Setup Steps

1. Standardize access levels and roles.
2. Use audit trail and history for approvals and investigations.
3. Define guidance for handling sensitive data in comments and Artifacts.

### Best Practices

* Limit Account Admin and Owner roles to a small set.
* Use least privilege for connectors and API tokens.
* Record approvals using consistent patterns, such as `Decision:` and `Approved by:`.

### Summary

Security and compliance controls focus on RBAC, auditability, and safe operational practices.

Related:

* [Understanding Access Levels](/organizations-and-projects/understanding-access-levels.md)
* [Audit Trail](/transformations/audit-trail.md)
* [Tracking Changes and Decisions](/collaboration-and-automation/tracking-changes-and-decisions.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.transform.ai/account-and-billing/security-and-compliance.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
