#Security #RBAC

Effective date: August 1, 2026

8.1 Core Principle

Hirfa applies the Principle of Least Privilege: every individual and system is granted only the minimum access necessary to perform its function — no more, no less — combined with Role-Based Access Control (RBAC) across all internal systems.

8.2 Personnel Access Controls

  • Access to production systems is restricted to authorized technical Personnel only, granted via named individual accounts — shared or generic accounts are prohibited to preserve accountability.
  • Mandatory two-factor authentication (2FA) is required for any account with access to Level 3 or Level 4 data (per the Data Classification Policy).
  • Access requests follow a formal approval workflow; standing/default access to production data is not granted merely by virtue of employment or title.

8.3 User (Client/Craftsman) Access Controls

  • Each Client and Craftsman can access only their own account data, booking history, and payment records.
  • No User can view another User's private data beyond what is intentionally exposed on public profiles (display name, rating, professional portfolio photos) or shared as part of an active booking (masked phone contact).

8.4 Periodic Access Review

All granted access privileges are reviewed at least quarterly. Access rights tied to a departed team member are revoked immediately upon offboarding, per Section 6.5.

8.5 Exceptional Access Requests

Any request for exceptional, one-off access to Level 4 (Restricted) data — for example, during an incident investigation — must be formally documented, requires dual approval from two authorized individuals, is time-boxed to the minimum duration necessary, and is fully recorded in the Access Log per the Audit Logs Policy (Section 12).

8.6 Third-Party and Vendor Access

Any third-party vendor (e.g., a cloud provider or contracted developer) granted access to Hirfa systems is subject to the same least-privilege principles, a signed data-processing/confidentiality agreement, and time-limited access that is revoked immediately upon completion of the engagement.