Provisioning

  1. Verify the request against an approved onboarding record (HR/IT).
  2. Create the user with the narrowest role; assign groups, not individuals, where possible.
  3. Require MFA enrolment on first login; require a passkey for privileged roles.
  4. Record the request id in the user's audit note.

RBAC

Map every user to a role from the table in the Administration Overview. Review role definitions

quarterly. Avoid "temporary" admin grants - if a break-glass grant is unavoidable, make it

time-boxed (<= 24 h) and alert on its use.

MFA administration

Deprovisioning (offboarding)

Run this checklist within 24 h of termination (immediately for cause):

Access reviews

Quarterly, or on role change. For each account: confirm it still needs access, has the least role,

has MFA, and belongs to a current employee/contractor. Log decisions; remove anything unconfirmed.

Departed-user accounts are a classic breach path. Treat the offboarding checklist as a hard

control, not a courtesy.

← Administrator Guide  ·  All guidelines