A cloud architect is configuring data protection for a set o…

A cloud architect is configuring data protection for a set of volumes on CBS. The architect has already created a protection group, added the volumes, and set both local snapshot schedule policies and replication schedules to a CloudSnap target.   What step should also be taken to protect from a rogue administrator?