Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Operations Manager

previous version on gdrive

Access Review Policy

1. Access Management & Review: myDRE Platform

1.1 Account Provisioning & Lifecycle Governance

To eliminate risks such as platform abuse, unauthorized system provisioning, or lateral movement via compromised service accounts, all user accounts on the myDRE platform are governed by an strictly regulated, manual provisioning lifecycle.

  • Authorization and Inception: Account creation is never executed dynamically or through unvetted automations. Valid requests must be formally initiated via:

  • System for Cross-domain Identity Management (SCIM) integrations.

  • The official administrative portal.

  • Execution Boundary: Account provisioning is executed exclusively by authorized anDREa Support staff following strict dual-custody verification rules.

  • Privileged Identity Management (PIM): Privileged, administrative, or directory-level roles must never be activated or inherited by automated applications, system identities, or service principles. PIM activation requires explicit manual authentication and authorization by validated personnel.

1.2 Telemetry, Auditability, and Behavior Monitoring

Operational telemetry is continuously aggregated to maintain platform integrity and fulfill systemic monitoring mandates.

  1. Security Event Aggregation: Security alerts and authentication signals are continuously monitored using core Microsoft security monitoring services.
  2. Investigation Triggers: The security operation teams proactively investigate anomalies on a case-by-case basis, strictly tracking:
  • Repeated Multi-Factor Authentication (MFA) challenges and failures.
  • Anomalous or geographically impossible sign-in behaviors.
  • High-risk user notifications triggered by integrated threat intelligence.
  1. Operational Cadence & Documentation: Telemetry logs and anomalous incidents are reviewed bi-weekly. Findings, justifications, and root-cause analyses are explicitly logged within the Periodic Security Controls.
  2. Remediation Paths: Verified risks prompt immediate protective actions, including temporary account restriction, out-of-band user verification, or advanced conditional blockades to contain potential account compromises.

1.3 Access Rights Management & Least Privilege Enforcement

  • Principle of Least Privilege (PoLP): Supplementary permissions beyond the baseline profile are denied by default. Entitlements are provisioned only upon documented operational necessity and are continuously validated.

  • Revocation Thresholds: Elevated or customized access rights are systematically revoked if:

  • The assigned permissions remain unused or dormant for extended periods.

  • Mandatory compliance conditions (such as security awareness certifications, data privacy training, or signed user agreements) are not fulfilled within specified time constraints.

  • Audit Cadence: Access configurations are reassessed bi-weekly and securely documented within the Periodic Security Controls ledger.

  • Cross-Reference: Operational details are mapped directly against the Overview User Management & Research Support governance standard.


2. Access Review Framework: myDRE Workspaces

2.1 Review Schedules and Cadence

Access validation within myDRE Workspaces utilizes a hybrid enforcement structure consisting of both automated platform triggers and ad-hoc supervisor controls:

  • Bi-Annual Automations: The platform automatically initializes a formal, system-wide access review cycle twice a year on January 15th and July 15th.
  • Ad-Hoc Mandates: Local Research Support (RS) components maintain the authority to trigger out-of-band access reviews at any time to mitigate emerging project risks.
  • Institutional Alignment: Local RS departments can configure localized periodic schedules tailored explicitly to the compliance cycles of their respective organizations.

2.2 Reminders, Timelines, and Blast Radius Isolation

When an access review window is opened, the system tracks specific execution deadlines. Failure by reviewers to finalize a workspace audit results in automated Blast Radius Isolation via the Restricted system role, stripping the unvetted users of interactive platform capabilities.

Review ContextFirst System ReminderEnforcement & Automated Containment Deadline
Ad-Hoc Review10 days prior to enforcement deadline15 days post-initiation
Bi-Annual Review55 days prior to enforcement deadline90 days post-initiation

Platform Automation & Visual Indicators

  • System-Triggered Inception: Bi-annual review cycles commence automatically on January 15th and July 15th.
  • Targeted Notification Routing: Automated system notifications are dispatched directly via email to Accountable and Privileged members of active workspaces, appending the specific metadata and workspace contexts required for the review.
  • Visual Telemetry: Identities currently under active review are tagged inside the workspace UI with a clear visual indicator (a question mark ? displayed next to their profile name) and are aggregated in the Access Reviews tab.
  • Exemptions: Accountable members are structurally exempt from the review flag (?) to preserve separation of duties and prevent unvalidated self-approval loops.

2.3 Authorized Dispositions and Remediation Actions

Administrative actions within a workspace access review window can be executed exclusively by authenticated Accountable and Privileged members. Local Research Support (RS) members support the review architecture and can initiate standard review cycles.

Reviewers must explicitly assign one of three technical dispositions to every flagged identity:

  1. Approve Selected:
  • Operational Context: Used only when the reviewer has verified that the user possesses a current, valid business requirement and matches their active role profile.
  • System Outcome: Maintains the user's active status and allows normal, uninterrupted execution of platform capabilities.
  1. Restrict Selected (Automated Containment Default):
  • Operational Context: Used when a user is confirmed as inactive or when a review window expires without explicit reviewer input.
  • System Outcome: Executes a Blast Radius Isolation. The identity is transitioned to the Restricted role, permanently stripping all functional, operational, and write capabilities within that workspace. The user's interface permissions are degraded to read-only visibility of workspace parameters and metadata lists.
  1. Delete Selected:
  • Operational Context: Used when a user has permanently completed their assignment, parted from the research project, or severed their relationship with the participating institution.
  • System Outcome: Executes absolute deprovisioning, scrubbing the identity entirely from the workspace access list and perimeter controls.

3. Access Review Framework: anDREa Corporate Employees

3.1 Corporate Governance Structure

Access governance for internal anDREa corporate environments, assets, and operational code repositories is managed through a strict organizational matrix:

  • Management Team: Holds ultimate fiduciary, regulatory, and policy oversight for corporate access authorization.
  • Asset Responsibles: Designated owners assigned to specific digital assets, source code repositories, and information systems who are responsible for continuous access validation.

3.2 Mandatory Governance Triggers

Internal access reviews for corporate identities are dynamically triggered by any of the following lifecycle events:

  • Personnel Onboarding and Transfers: The formal addition of employees or shifts in corporate roles, titles, and operational scopes.
  • Personnel Offboarding: Immediate revocation of all access footprints upon contract termination or organizational departure.
  • System Architecture Adjustments: Deployments, configuration changes, or structural migrations within the anDREa software ecosystem and core cloud architecture.

4. Standardized Review Criteria & Audit Guidelines

To ensure consistency across both localized myDRE Workspaces and internal anDREa corporate directories, all authorized reviewers must explicitly audit access permissions against the following core security criteria:

  • Principle of Least Privilege (PoLP): Verify that all assigned user privileges are restricted to the minimum access required to complete designated operational functions.
  • Role-Based Access Control (RBAC) Alignment: Ensure that assigned groups, security parameters, and repository rights accurately reflect the user's current corporate role or research mandate.
  • Segregation of Duties (SoD): Analyze access profiles to detect, document, and eliminate conflicting administrative privileges or overlapping permissions that could induce corporate fraud or unmitigated security risks.
  • Dormant Identity Liquidation: Proactively isolate or permanently remove stale accounts, unutilized access paths, or credentials belonging to individuals who are no longer active within the platform or corporate framework.