Seen CRM
Access Control Policy
| Document number | SEEN-POL-02 |
|---|---|
| Version | 1.0 |
| Effective date | On approval |
| Policy owner | Seen CRM Management |
| Approved by | Seen CRM Management |
| Classification | Public |
| Next review | Within 12 months of the effective date |
1. Purpose
This policy ensures that access to the Seen CRM platform and to customer data is limited to authorised people, for authorised purposes.
2. Scope
This policy applies to all user accounts on the platform, to Seen CRM's administrative accounts, and to the systems that operate the platform.
3. Policy
- Least privilege. Each person receives only the access their role requires.
- Customer control. Each customer's administrators manage their own users, roles and permissions.
- Passwords. Passwords are stored only in a one-way protected form. Repeated failed sign-in attempts temporarily block further attempts.
- Multi-factor authentication. Required for every Seen CRM administrative account. Customers may require it for their own users.
- Single sign-on. Customers may allow their users to sign in with Google or Microsoft.
- Sessions. Sessions expire automatically. Deactivating a user or changing their password ends their active sessions. Sensitive actions require the password to be entered again.
- Support access. Seen CRM accesses a customer's workspace only to provide support, and every such access is recorded in that customer's own audit log.
- Leavers. Access is removed on the day a person leaves or no longer needs it.
- Reviews. Administrative access is reviewed at least every three months.
4. Responsibilities
Management grants and reviews administrative access. Customer administrators are responsible for the access they grant within their own workspace.
5. Exceptions
Any exception must be approved in writing by management, with a stated reason and an end date.
6. Review
This policy is reviewed at least once a year, and after any major security incident.
7. Contact
Questions about this policy: info@seencrm.com