Effective date: August 1, 2026
Hirfa applies the Principle of Least Privilege: every individual and system is granted only the minimum access necessary to perform its function — no more, no less — combined with Role-Based Access Control (RBAC) across all internal systems.
All granted access privileges are reviewed at least quarterly. Access rights tied to a departed team member are revoked immediately upon offboarding, per Section 6.5.
Any request for exceptional, one-off access to Level 4 (Restricted) data — for example, during an incident investigation — must be formally documented, requires dual approval from two authorized individuals, is time-boxed to the minimum duration necessary, and is fully recorded in the Access Log per the Audit Logs Policy (Section 12).
Any third-party vendor (e.g., a cloud provider or contracted developer) granted access to Hirfa systems is subject to the same least-privilege principles, a signed data-processing/confidentiality agreement, and time-limited access that is revoked immediately upon completion of the engagement.