| Identity | Authenticated users and integrations vs unauthenticated requests | Auth provider integration, token and session validation, scoped access |
| Network | Internet edge vs application ingress | TLS-required connections, edge protections, controlled endpoint exposure |
| Application | Tenant and workspace operations | Tenant-scoped authorization and role-based access patterns |
| Data | Control-plane metadata vs customer source telemetry systems | Data minimization model and bounded storage scope |
| Secrets | Runtime services vs credential material | Managed secret stores with least-privilege access |