Policies Internal operating policies
Access Control Policy
How internal access to production systems, user data, and admin functions is granted, reviewed, and revoked.
- Version
- 0.1.0
- Effective
- May 20, 2026
- Last reviewed
- May 20, 2026
- Review cycle
- every 6 months
- Master Policy Index entry
- §4 #62
Policy text
Internal access is structured. The Access Control Policy defines the least-privilege default, the role-based access tiers, the MFA requirement, the quarterly access review, the immediate-revocation triggers (departure, role change, security incident), and the audit-log requirements that connect access events to identifiable individuals.
It applies to Map.ca staff, contractors, vendors with production access, and the security team that operates the access-control system.
Principles this policy enforces
- Collect less, protect more
- Public data and personal data are not the same thing
- Community benefit must survive scale
What it requires
- Default to least privilege.
- Review access quarterly and on every role change.
What it forbids
- Do not share credentials between people.
- Do not grant indefinite admin access without review.
How it applies
- Map.ca staff
- Contractors
- Vendors with production access
- Security team
References
- PIPEDA — Safeguards principle
Related policies
Security Policy
How Map.ca protects accounts, infrastructure, secrets, and operational data day to day.
Audit Logging Policy
What Map.ca logs for audit purposes, how those logs are protected, retained, and used.
Vendor Security Policy
Security requirements Map.ca holds vendors to before, during, and after engagement.