← Governance framework
Platform Operations
Access Control and Admin Role Policy
Rules for assigning and reviewing platform roles including admin, verifier and operator functions.
- Version
- v1.0
- Effective
- 2026-07-19
- Last reviewed
- 2026-07-19
- Next review
- 2027-07-19
- Owner
- Head of Security
- Approver
- Executive Team
Anchored by content hashissued 2026-07-29
Payload hash
b278032f523dbc31f97afc5ce3f40ad174a66f95e4173f0506dcb450bfcf8e33SHA-256 digest of the receipt content
Issuer AID
EP1_FGkcwfHAuih6VUzv9kgAVBvvSoaswSUao61lkxhEParty that issued this receipt
ImpactMiles handle
audit:governance:b278032f523dbc31This receipt is anchored by content hash. A resolvable credential SAID is not available for this record.
Applies to
- user_roles table
- Admin operator accounts
Jurisdictions
- Hong Kong (PDPO, IRD s.88)
- United Kingdom (UK GDPR, DPA 2018)
- European Union (GDPR)
- Singapore (PDPA)
- Australia (Privacy Act 1988)
- Japan (APPI)
- Wider APAC per country taxonomy
How this is applied in-product
- user_roles separate table with has_role security-definer function
- Admin actions logged to admin_audit_log
- Least-privilege server-fn design
1. Role Model
- participant, corporate, charity - domain users.
- admin - platform operators, further scoped by task in server-fn logic.
- service_role - reserved for server-side automation; never issued to humans.
2. Segregation of Duties
The user who submits KYB evidence cannot approve their own verification. Admin approval requires a second-person review for material actions.
3. Review
Access rights are reviewed quarterly and immediately upon role change or termination.
Questions or concerns about this policy? Contact the DPO.