maximal
SecurityMaximal does not expose arbitrary shell execution. Remediation is limited to typed action handlers, contract allowlists, blast-radius checks, pre-action snapshots, verification, and audit replay.
Managed identity
Clerk handles invite-only sign-in, Google OAuth, session revocation, and workspace membership. Maximal separately enforces tenant, approval, and AWS-role authorization.
Connector boundary
AWS access uses scoped cross-account roles. Slack and GitHub installation credentials are stored per tenant, and OAuth setup state is browser-bound and single-use.
Auditability
Incident events are hash-chained and replayable so each decision and action can be inspected after the fact.