Access Control Policy
1. Policy Purpose
This policy governs provisioning, maintenance, and revocation of access rights to Weblo TTS systems.
2. Least Privilege Principle
Users are granted only the minimum access required to perform their duties.
3. Account Lifecycle
- Account creation based on approved requests.
- Permission updates upon role changes.
- Immediate deprovisioning when cooperation ends.
4. Multi-Factor Authentication
MFA is mandatory for administrative accounts and access to critical systems.
5. Password and Secrets Management
Passwords and secrets must meet complexity, rotation, and secure storage requirements.
6. OAuth Tokens and API Access
OAuth2 tokens for TikTok Shop integration are stored encrypted and available only to authorized application processes.
7. Access Reviews
Access rights are reviewed and documented at least quarterly.
8. Logging and Audit
Privileged actions, login attempts, and access-related configuration changes are logged for auditability.
9. Policy Enforcement
Violations are investigated and followed by corrective and disciplinary measures proportionate to risk.
Document Approval
This document has been approved by the Management Board of TIME4IT Sp. z o.o.
Version: 1.0
Approval date: 22 June 2026
Contact
For questions regarding this document, security or privacy:
TIME4IT Sp. z o.o.ul. Plonowa 24I/2, 05-500 Nowa Wola, Polska
KRS: 0001140137 · NIP: 1231569806 · REGON: 540441588
e-mail: [email protected]