You are responsible for a new application that handles customer profiles and internal admin actions. It runs as a set of services behind an API gateway, stores data in a managed database, and calls a few internal services over the network. A recent review found that authentication, secrets handling, and logging were all left to the default settings.