Understand the information
Identify the records the workflow needs and where sensitive information appears. Discuss who owns that information, where it may be processed and which sources should remain outside the proposed scope.
Platform Security
A practical approach to access, sensitive information and review in each engagement.
Talk about your businessBuilt around your team.
The approach
Every business brings different systems and information into a workflow. We work through the access and handling requirements with your team, and agree the controls and hosting scope before putting the workflow into use.
Identify the records the workflow needs and where sensitive information appears. Discuss who owns that information, where it may be processed and which sources should remain outside the proposed scope.
Define the permissions needed for each integration and role. Separate access to view information from access to change it, and agree who can approve actions involving important business records.
Document the hosting arrangement, access management and incident responsibilities relevant to the engagement. Review requirements with your technical and compliance teams; the final controls depend on the system and agreed scope.
In practice
For a people workflow, employee documents and payroll inputs are reviewed as separate access needs. Only the information required for the agreed task is included in the proposed integration and review path.
An example workflow, shaped to the systems and responsibilities of your business.