| Field | Value |
|---|---|
| Owner | IDEAL Lab IT administrator |
| Verified | 2026-08-04 |
| Review by | 2027-02-04 |
Required Baseline#
Everyone working with IDEAL Lab systems or repositories must:
- use personal ETH/GitHub accounts and MFA;
- complete the IT and Research Safety Core;
- complete capability endorsements relevant to their responsibilities;
- use approved project repositories and storage locations;
- protect secrets, unpublished work, personal data, and partner material;
- review AI-generated commands, diffs, and claims before use;
- report credential, confidentiality, access, data-loss, and shared-resource incidents promptly;
- provide a reproducible project handover.
Access Principles#
- Grant the least access needed for the work.
- Supervisors approve project membership and information access.
- Lab IT implements supported GitHub, NAS, Euler, and machine access.
- Accounts and private keys are never shared.
- Guest/collaborator access must be sponsored and removed when no longer needed.
- Exceptions must state owner, reason, scope, and expiry.
System Boundaries#
- GitHub stores source, tests, configuration, and documentation, not secrets or large research artifacts.
- NAS and approved Euler storage hold research data according to ownership and lifecycle decisions.
- Blade is a shared interactive Windows workstation, not permanent storage or an HPC replacement.
- Euler login nodes manage jobs; compute runs through Slurm.
- GPU and long interactive use follow the Euler share policy.
Departures And Handover#
Before a project member leaves, the supervisor assigns the next owner, verifies code/data/result locations, transfers service ownership, removes unnecessary access, and confirms that no critical artifact remains only in personal or temporary storage.