Tutorials/Identity and Access Management Policy

Identity and Access Management Policy

Document control

Field Value
Document status Active policy document
Owner Security / Operations
Approver Management
Review frequency Annual or on material change
Classification Customer-shareable

Purpose

Ensure access to systems and data is authorized, traceable, least-privileged, and removed when no longer required.

Access principles

Access must be based on business need, approved by an owner, limited to the minimum privileges required, and reviewed periodically. Shared accounts should be avoided. Privileged access requires additional scrutiny and monitoring.

Provisioning

Access requests should capture user, role, system, business purpose, approval, duration, and privilege level. Access should be granted through role-based groups where feasible.

Authentication

Strong authentication must be used for business systems. MFA should be used for administrative, remote, cloud, repository, and sensitive system access where supported.

Privileged access

Administrator permissions must be restricted to authorized personnel, used only for approved purposes, and reviewed more frequently. Emergency access should be logged and reviewed.

Joiner/mover/leaver process

Access must be granted during onboarding, adjusted when roles change, and revoked promptly during offboarding or contract completion.

Service accounts and API keys

Service accounts must have owners, purpose, limited permissions, credential rotation, and revocation process. Keys must not be shared or stored insecurely.

Evidence to maintain

Access request/approval records, access review evidence, MFA evidence, privileged user list, offboarding checklist, and service account inventory.

Need help with your workflow setup?

If you're stuck or want help applying these guides to your setup, our team can assist with configuration, customization, and workflow implementation.