> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mettlestate.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security & Permissions

> Authentication, role-based access, and audit logging that protect players and funds.

## Authentication

* Sign-in uses current security standards, with sessions established securely and validation applied on both the client and the server
* Available sign-in methods are configured per deployment
* Protected pages redirect you to sign in rather than exposing anything to an unauthenticated visitor

## Role-based access

Teams and organisations both use roles, so people only get the access their position requires. An organisation owner and a team reserve do not see or control the same things, and permissions covering money are separated from permissions covering rosters.

See [Team Structure & Roles](/teams/structure) and [Organisation Roles & Permissions](/organisations/roles).

## Audit logs

Sensitive actions are recorded — roster and ownership changes, permission changes, and movements of money. Organisation and team leadership can review this history, which means a disputed change can be traced rather than argued about.

## Protecting your own account

* Use a strong, unique password
* Complete any verification a deployment requires before withdrawing funds
* Review your organisation's activity log if a change appears that you did not expect
