Identity and Access Controls
Access Lifecycle
Access is provisioned according to role and business need, reviewed periodically, and removed when it is no longer required. Reviews cover privileged access, role appropriateness, service accounts, and exceptions to standard access patterns.Multi-Factor Authentication
Multi-factor authentication is required for administrative access to critical systems where supported. This includes infrastructure consoles, source-control administration, database administration, and security-sensitive SaaS applications.Least Privilege and Accountability
Avoca uses least-privilege principles throughout its environment:- Individual accounts are preferred over shared credentials
- Elevated permissions are granted only when required
- Centralized identity and single sign-on are used where appropriate
- Service accounts and integration credentials are restricted and managed separately
- Access changes and privileged actions are logged where supported