← Governance framework
Platform Operations

Access Control and Admin Role Policy

Rules for assigning and reviewing platform roles including admin, verifier and operator functions.

Version
v1.0
Effective
2026-07-19
Last reviewed
2026-07-19
Next review
2027-07-19
Owner
Head of Security
Approver
Executive Team
Anchored by content hashissued 2026-07-29
Payload hash
b278032f523dbc31f97afc5ce3f40ad174a66f95e4173f0506dcb450bfcf8e33
SHA-256 digest of the receipt content
Issuer AID
EP1_FGkcwfHAuih6VUzv9kgAVBvvSoaswSUao61lkxhE
Party that issued this receipt
ImpactMiles handle
audit:governance:b278032f523dbc31

This receipt is anchored by content hash. A resolvable credential SAID is not available for this record.

Applies to

  • user_roles table
  • Admin operator accounts

Jurisdictions

  • Hong Kong (PDPO, IRD s.88)
  • United Kingdom (UK GDPR, DPA 2018)
  • European Union (GDPR)
  • Singapore (PDPA)
  • Australia (Privacy Act 1988)
  • Japan (APPI)
  • Wider APAC per country taxonomy

How this is applied in-product

  • user_roles separate table with has_role security-definer function
  • Admin actions logged to admin_audit_log
  • Least-privilege server-fn design

1. Role Model

  • participant, corporate, charity - domain users.
  • admin - platform operators, further scoped by task in server-fn logic.
  • service_role - reserved for server-side automation; never issued to humans.

2. Segregation of Duties

The user who submits KYB evidence cannot approve their own verification. Admin approval requires a second-person review for material actions.

3. Review

Access rights are reviewed quarterly and immediately upon role change or termination.

Questions or concerns about this policy? Contact the DPO.

Related policies