WriteChoice

Access Control Policy

Access to client information is granted only to the people working on that engagement, protected by two-factor authentication, and removed as soon as it is no longer needed.

Version 1.0 Effective September 2026 Owner Security Officer (COO) Review At least once a year Contact security@writechoice.io

2.1 Principles

  • Least privilege: personnel get only the access their current work requires, and only to the clients they are assigned to.
  • Individual accounts: every person uses their own named account. Shared logins are not allowed; if a client provides a shared credential, it is stored in the password manager and shared only with the engagement team.
  • Company accounts: client work happens only through WriteChoice-managed accounts or accounts the client provisions, never personal accounts.

2.2 Authentication

  • Two-factor authentication is enforced on Google Workspace and GitHub, and required on every other approved tool that supports it.
  • Passwords are unique per service, generated by and stored in the company password manager.
  • Credentials, API keys, and tokens are never sent over chat or email in plain text; they are shared through the password manager.

2.3 Granting, changing and removing access

EventActionResponsibleDeadline
Person joinsCompany accounts created; policies acknowledged; device baseline confirmedSecurity OfficerBefore first access to client material
Person assigned to a clientAccess to that client's tools and repositories requestedProject leadWhen assigned
Person leaves an engagementAccess to that client removedProject leadWithin 2 business days
Person leaves WriteChoiceAll company and client access revoked; company data removed from the deviceSecurity OfficerWithin 1 business day of last working day

2.4 Access reviews

Every quarter, the Security Officer and project leads review who has access to each client's systems and to company tools, and remove access that is no longer needed. The date and outcome of each review are recorded.

2.5 Client systems

When a client grants access to its repositories, sandbox environments, or tools, WriteChoice follows the client's own access rules in addition to this policy, and asks the client to remove access at the end of the engagement.