Skip to main content

Access Reviews Policy

Document control

FieldValue
OwnerRon Benisty — CTO & CSO (ron.b@iontwrks.com)
StatusApproved
Version1.0
ClassificationConfidential
Approved byRon Benisty — CTO & CSO
Approval date2026-05-26 (Tuesday)
Last reviewed2026-05-26
Review cycleAnnual — next review due May 2027
Parent policySecure SDLC (SSDLC)

Satisfies ISO/IEC 27001:2022 A.5.18 (access rights — provisioning, review, removal) and SOC 2 Type II CC6.1–CC6.3 (logical-access provisioning, modification, removal). Closes the access-review portion of the SSDLC gap analysis (referenced under §4 of the SSDLC umbrella).


1. Purpose

Confirm — on a documented cadence — that every identity with access to S.E.T's systems still needs it at the privilege level it has, and remove access promptly where it is no longer warranted.

2. Scope

SystemIdentities reviewedReviewer
GitHub (org + repos)All collaborators (S.E.T team + third-party dev firm members), bot/service accounts, deploy keys, Personal Access Tokens, GitHub AppsCTO & CSO
AWS IAM (management, shared-services, set-nonprod, set-prod-eu, future set-prod-il)IAM users, IAM roles, OIDC trust relationships, access keys, MFA statusCTO & CSO
WorkOSAdmin users + each customer Organization's ownerCTO & CSO
Logz.ioAccount members, alert channels, API keysCTO & CSO
CloudflareOrg members, API tokensCTO & CSO
Sub-processors with admin consolesOne named owner per processorCTO & CSO

3. Cadence

FrequencyActivitySource / cross-reference
MonthlyGitHub audit-log review — review the rolling 30-day audit log for unusual access patternsSupply Chain §3
QuarterlyFull collaborator / identity reconciliation per system — for every identity, confirm: (a) still employed / contracted, (b) still needs access, (c) at the right privilege levelThis policy
QuarterlyIAM Access Analyzer review — investigate every flagged overly-permissive policyEnvironments §IAM
AnnuallyRight-to-audit exercise against the third-party dev firm — confirm their developer roster matches our GitHub collaborator listSupply Chain §3 + Audit Testing Scope §3

4. Off-boarding SLA

  • Departing S.E.T-team member: all access revoked within 24 hours of departure decision — GitHub, AWS IAM, WorkOS, Logz.io, Cloudflare, hardware tokens collected, sub-processor admin consoles.
  • Departing contractor developer: dev firm notifies within the agreed contract window; S.E.T removes GitHub access within 24–48 hours (Supply Chain §3 contract clauses).
  • Compromised credential: revoked immediately as part of Incident Response.

5. Privilege model

  • Least privilege at all times — every identity holds the minimum role required.
  • Separation of duties preserved per the Separation of Duties Policy.
  • No long-lived AWS access keys where avoidable — prefer assume-role with MFA and temporary credentials (Environments §IAM).
  • MFA mandatory on every identity that supports it (GitHub, AWS IAM, WorkOS).
  • Service accounts / bots are documented — purpose, owner, secret rotation cadence.

6. Evidence

Each cycle produces:

  • A signed review record (the reviewer's checklist).
  • A diff of identities added / removed / modified vs. the previous cycle.
  • A short note for any identity intentionally kept at elevated privilege.

Retained ≥ 12 months per the Evidence Collection & Retention Policy. SOC 2 Type II will sample these records.

7. Document change history

VersionDateAuthorDescription of changeApproved by
1.02026-05-26Ron Benisty (CTO & CSO)Initial version — establishes the access-review cadence and scope.Ron Benisty (CTO & CSO)