This document is a technical report outlining the application security standards for the Expresia application. It details the policies regarding password management and permissions management, which are essential for maintaining the security of user accounts. The policy statement emphasizes the importance of managing passwords and roles to protect against unauthorized access and ensure users have appropriate access to resources. The document defines key terms related to the Expresia application and instance, and it describes the password management policy, including requirements for password strength and the use of multi-factor authentication. Additionally, it outlines the permissions management policy, detailing default user roles and the ability to create custom user roles. The report provides a structured approach to managing user accounts and permissions, ensuring compliance with best practices in application security.