Private files are managed through the documents collection and S3-backed storage. Public CMS assets belong in media. Production secrets must stay in AWS Secrets Manager and must not be stored in Payload records.

Paid AI usage is disabled by default. When AI features are enabled by an administrator, usage must follow configured budgets, approval rules, and data-scope controls.

This seeded policy is a starter record for local development and should be reviewed by counsel before production launch.