Policies Internal operating policies

Access Control Policy

How internal access to production systems, user data, and admin functions is granted, reviewed, and revoked.

Version
0.1.0
Effective
May 20, 2026
Last reviewed
May 20, 2026
Review cycle
every 6 months
Master Policy Index entry
§4 #62

Policy text

Internal access is structured. The Access Control Policy defines the least-privilege default, the role-based access tiers, the MFA requirement, the quarterly access review, the immediate-revocation triggers (departure, role change, security incident), and the audit-log requirements that connect access events to identifiable individuals.

It applies to Map.ca staff, contractors, vendors with production access, and the security team that operates the access-control system.

Principles this policy enforces

  • Collect less, protect more
  • Public data and personal data are not the same thing
  • Community benefit must survive scale

What it requires

  • Default to least privilege.
  • Review access quarterly and on every role change.

What it forbids

  • Do not share credentials between people.
  • Do not grant indefinite admin access without review.

How it applies

References