Access control is most effective when it follows the role and the workflow. Broad, permanent access may feel convenient, but it makes oversight harder and increases the impact of mistakes.

Before access

Confirm identity through the provider’s approved process, complete required training, document the role and obtain owner approval for each system.

During access

Use individual accounts, multifactor authentication where supported, least privilege and managed devices. Review unusual activity and failed sign-ins through the system owner’s normal monitoring.

When work changes

Reassess access after role changes, extended leave and project completion. Do not let temporary permissions become permanent by default.

At exit

Disable accounts promptly, recover devices, rotate shared operational credentials through the authorised owner, preserve required records and confirm data return or disposal.