Users and Roles
Enforce role discipline and least-privilege controls across administrative workflows.
Access control quality determines how safely your teams can operate. Role assignment must be intentional, reviewable, and reversible.
Access governance goals
These goals define a healthy role model.
- Users only have permissions required for current responsibilities.
- Temporary access is time-bound and tracked.
- Access reviews are regular and evidence-backed.
Role assignment workflow
Use this flow whenever granting or changing access.
Assign base role based on documented responsibility.
Apply scoped exceptions only when required and approved.
Set review date for temporary or elevated access grants.
Revalidate role fit after onboarding, transfer, or offboarding events.
Governance controls
Apply these controls to prevent privilege creep.
- Revoke stale invitations and unused elevated accounts.
- Keep break-glass or emergency paths tightly controlled.
- Document owner and reason for every elevated grant.
- Verify changed users can perform required actions and nothing beyond scope.
Least privilege requirement
Do not assign broad admin access for short-term convenience. Temporary tasks must use temporary, scoped permissions.
Next steps
- Validate organization hygiene in Organizations.
- Validate capability impact in Subscriptions.
- Monitor access-related incidents in Monitoring.
Last updated on