Protection across the workflow
Least-privilege access
Roles are intended to limit sensitive actions and views to people whose responsibilities require them.
Administrative boundaries
Higher-impact account, company and access-management actions are reserved for authorised roles.
Controlled team management
Authorised managers can register agents, while elevated roles govern broader account and permission changes.
Prompt access removal
Deactivation and offboarding controls help stop former team members from continuing to enter the workspace.
Actions customers should take
- Assign the lowest role that still allows the person to complete their job.
- Review roles whenever responsibilities, departments or employment change.
- Never share one account between several people.
- Remove or deactivate access promptly during offboarding.
Visible signs and normal behaviour
- A user may see fewer pages or actions than a manager or administrator.
- Role changes should be made by an authorised company administrator.
- If access appears broader than expected, stop using the affected function and report it.
Controls reduce risk; they do not eliminate it.
No single control guarantees protection against every threat. Secure use also depends on accurate access decisions, protected devices, appropriate staff training and prompt reporting. We avoid claiming certifications that have not been independently verified.
