# Plex customers

Customer operations are explicit actions in `PlexOperations`, protected by legacy permissions and ownership checks. A customer is retained in `customers`; suspension and remote revocation are separate actions. Passwords and API tokens are never displayed or stored by the phase 3 workflow. Every mutation records a UUID, movement, and a durable encrypted journal entry.
