DOC HC-02 · ACCESS STANDARD
How I access your systems.
Sent to every client before work starts. Published here because you should not have to ask.
The rules
- Named access only. I get my own account or a dedicated cross-account role. I never use a shared login, a team credential, or anyone's personal account.
- Least privilege for the job. Cost work starts read-only. Write access is scoped to the resources in the SOW and granted only when we reach the step that needs it.
- AWS specifically: a cross-account IAM role in your account that I assume from mine. You see every action in CloudTrail under that role. I will send a role template; you review it before creating anything.
- No credentials in email or Slack. Access is granted through the provider's own invite/role mechanism. If a secret must move, it moves through a one-time-link tool, never chat history.
- Everything is logged on your side. My access runs through your systems' own audit logs, so you can verify what I did without trusting my word.
- Revocation at close. The final deliverable includes a list of every access grant, so you can revoke them all in minutes. Revoking is your step on purpose: your systems, your off switch.
What I ask of you
- Grant access before the start date in the SOW (this is the most common cause of delay)
- Tell me about any system where access is monitored or restricted by policy, so we do it their way