2.1 Principles
- Least privilege: personnel get only the access their current work requires, and only to the clients they are assigned to.
- Individual accounts: every person uses their own named account. Shared logins are not allowed; if a client provides a shared credential, it is stored in the password manager and shared only with the engagement team.
- Company accounts: client work happens only through WriteChoice-managed accounts or accounts the client provisions, never personal accounts.
2.2 Authentication
- Two-factor authentication is enforced on Google Workspace and GitHub, and required on every other approved tool that supports it.
- Passwords are unique per service, generated by and stored in the company password manager.
- Credentials, API keys, and tokens are never sent over chat or email in plain text; they are shared through the password manager.
2.3 Granting, changing and removing access
| Event | Action | Responsible | Deadline |
|---|---|---|---|
| Person joins | Company accounts created; policies acknowledged; device baseline confirmed | Security Officer | Before first access to client material |
| Person assigned to a client | Access to that client's tools and repositories requested | Project lead | When assigned |
| Person leaves an engagement | Access to that client removed | Project lead | Within 2 business days |
| Person leaves WriteChoice | All company and client access revoked; company data removed from the device | Security Officer | Within 1 business day of last working day |
2.4 Access reviews
Every quarter, the Security Officer and project leads review who has access to each client's systems and to company tools, and remove access that is no longer needed. The date and outcome of each review are recorded.
2.5 Client systems
When a client grants access to its repositories, sandbox environments, or tools, WriteChoice follows the client's own access rules in addition to this policy, and asks the client to remove access at the end of the engagement.
