Manager Keys [repack]: Content

Do not give every content manager delete permissions. Do not give service accounts write access if they only read. Segment keys by function: editorial keys, publishing keys, admin keys.

In practical terms, if a website or app displays text, images, or video, the person holding the CMK can change it in real-time. content manager keys

A content manager must track and measure the performance of content to refine the content strategy. This includes: Do not give every content manager delete permissions

Every action taken with a CMK must be logged with immutable timestamps, user ID (or service name), and the exact content change. Logs should go to a separate, read-only system. admin keys. In practical terms