Skip to main content

Access standard

Every access path has an owner and an exit.

Access follows the work, not a title. A request must identify the person, system, client boundary, purpose, least privilege required, approver, start, review date, and removal condition.

ForPeople conducting policy, privacy, security, or access review

FocusControls, ownership, evidence, and review paths

Access lifecycle

  1. Request: tie access to an approved role and work boundary.

  2. Approve: confirm identity, purpose, data class, environment, duration, and reviewer.

  3. Provision: use individual credentials, least privilege, MFA where supported, and auditable group membership.

  4. Review: revalidate need, privilege, conflicts, inactivity, and expiry.

  5. Change: reopen approval when role, scope, system, data, or location changes.

  6. Remove: revoke access at transfer, role change, inactivity threshold, incident, or engagement close.

  7. Verify: retain removal and exception evidence with the handoff record.

Shared credentials, unrecorded privilege, indefinite access, and unmanaged production entry are outside the standard.

Review security and data handling

Start an access-control review.