OAuth, service-account, or other supported access patterns are selected with the customer administrator. Requested scopes follow least-privilege design, while credential storage, rotation, revocation, consent, and ownership are documented using the controls available in the selected architecture.