Access control
What role-based access controls exist?
How to answer this security questionnaire question, with an expert response your security or GRC team can adapt.Expert answer
Implement RBAC so users receive only the permissions their role requires, with segregation of duties for sensitive functions. Review role assignments periodically and support customer-configurable roles where relevant.What the security reviewer is checking
Unlike the abstract access-model question, this phrasing usually asks you to enumerate: which roles exist, what each can do, and where the boundaries are. If the question targets your product, the reviewer — often preparing their own least-privilege rollout — wants the actual role list, whether permissions are fixed or customizable, whether roles can be scoped to subsets of data (projects, workspaces, teams), and what governance features help their admins: audit visibility into role changes, protection against removing the last administrator, and SCIM or IdP group mapping to automate assignment. If it targets your internal controls, the answer should enumerate real internal role tiers rather than restating policy language.Example response you can adapt
This is an illustrative template, not a real vendor's security posture. Replace every claim with what is actually true for your organization before submitting it.In the product, access is governed by a defined role hierarchy that customer administrators manage per organization. Standard roles include Administrator (full organization management including membership, SSO, and security settings), Manager (create and manage content and workflows without security administration), Member (day-to-day use of permitted workspaces), and Read-only Viewer; roles can be scoped to specific workspaces, so a user may be a Manager in one and a Viewer in another. Role assignments can be automated by mapping identity provider groups through SSO or SCIM, and every role grant, change, and removal is written to the organization audit log that administrators can review and export. Safeguards prevent removing the final administrator and require confirmation for privilege escalations. Internally, our workforce follows the same discipline: function-based roles grant least-privilege system access, production access is restricted to a small approved group with just-in-time elevation, and all grants are recertified in quarterly access reviews.
Evidence reviewers expect you to attach
- Product documentation listing roles and their permission sets
- Screenshot of the role management and audit log interface
- SCIM / IdP group-mapping documentation for automated role assignment
- Internal access control policy with role definitions and review cadence
Follow-up questions reviewers ask next
- Can we create custom roles, or are the preset roles fixed?
- Can roles be scoped per project or workspace rather than organization-wide?
- Are role changes captured in an audit log we can export?
- Can role assignment be driven automatically from our IdP groups?
- Which of your internal roles can access customer data, and under what conditions?
Answer every security questionnaire in minutes
Wolfia drafts accurate, cited answers to security questionnaires and RFPs from your existing documentation. See it work on your own questions.Book a demoRelated access control questions
Is multi-factor authentication (MFA) required for all users?What is your password policy?How do you handle employee offboarding?Do you perform background checks on employees?How do you manage access to production systems?Do you support single sign-on (SSO) for customers?
Browse the full security questionnaire question library