← Return to Cardinal Claims

CARDINAL CLAIMS POLICY

Support Access Policy

Effective and last updated September 21, 2026

Operational policy for Cardinal Claims. Organization-specific legal, contractual, and retention obligations continue to apply.

Customer control

Each customer organization keeps its own administrators, users, roles, and isolated records. Cardinal support does not use a master customer login and cannot automatically view every organization’s claims, drivers, customers, evidence, communications, or recovery records.

Explicit approval

An organization administrator must approve a named Cardinal support user for a defined support purpose, data scope, and expiration time before access begins. Approval for one organization never authorizes access to another organization.

Least privilege

Support access is normally read-only and limited to the minimum records needed to resolve the approved request. Any write capability must be separately justified, explicitly approved, limited in scope, and revoked when the support window ends.

Auditability and expiration

The support identity, approving administrator, reason, start time, expiration, records accessed, and actions taken must be recorded. Access expires automatically or is revoked when the approved work is complete.

Emergency access

No unapproved emergency or break-glass access is available. Any future emergency-access process requires separate security review, customer notification rules, time limits, and complete audit evidence before activation.

Support requests

Authorized administrators may contact apps@cardinalecosystem.com to request or revoke a support session. Sending a support request does not itself grant Cardinal access.

Return to Cardinal Claims