CARDINAL CLAIMS POLICY
Support Access Policy
Effective and last updated September 21, 2026
Customer control
Each customer organization keeps its own administrators, users, roles, and isolated records. Cardinal support does not use a master customer login and cannot automatically view every organization’s claims, drivers, customers, evidence, communications, or recovery records.
Explicit approval
An organization administrator must approve a named Cardinal support user for a defined support purpose, data scope, and expiration time before access begins. Approval for one organization never authorizes access to another organization.
Least privilege
Support access is normally read-only and limited to the minimum records needed to resolve the approved request. Any write capability must be separately justified, explicitly approved, limited in scope, and revoked when the support window ends.
Auditability and expiration
The support identity, approving administrator, reason, start time, expiration, records accessed, and actions taken must be recorded. Access expires automatically or is revoked when the approved work is complete.
Emergency access
No unapproved emergency or break-glass access is available. Any future emergency-access process requires separate security review, customer notification rules, time limits, and complete audit evidence before activation.
Support requests
Authorized administrators may contact apps@cardinalecosystem.com to request or revoke a support session. Sending a support request does not itself grant Cardinal access.