Access governance
RBAC & Privileged Access
Role-based permissions for business users, EDD analysts, compliance reviewers, privacy/DPO, auditors and platform administrators, with PAM for privileged functions.
6Separated duties
2PAM required
RequiredAll interactive users
QuarterlyPlus event-driven
| Permission | Onboarding | EDD Analyst | Compliance Checker | Privacy / DPO | Auditor | Platform Admin |
|---|---|---|---|---|---|---|
| View merchant case | ||||||
| View raw documents | ||||||
| Run screening | ||||||
| Change module threshold | ||||||
| Make EDD decision | ||||||
| Approve high-impact decision | ||||||
| Export evidence | ||||||
| Process correction/deletion | ||||||
| View audit log | ||||||
| Manage connector secrets |
PAM controls
- Time-bound privileged session.
- Approval for production config changes.
- Session/activity logging.
- Secret vault; no shared admin credentials.
Segregation of duties
- EDD maker ≠ high-impact checker.
- Model developer ≠ production approver.
- Connector secret admin ≠ business reviewer.
- Auditor is read-only.
Access review
Last review: 31 Jul 2026
Exceptions: 2 temporary roles expiring this week.