Mon–Fri 9am–5pm · Contract clients: urgent support 6am–10pm, every dayLeeds 0113 8000 192 · National 0330 1700 092

User Access Control

Not everyone needs to see everything. Access control means staff can reach the data their job needs, and nothing else, which limits the damage from mistakes, leavers and stolen passwords.

Talk to usSee pricing

Every business holds data that should not be open to all staff: HR records, payroll and accounts, client records, and supplier details. Payroll, for example, should be visible to HR and finance, not to everyone.

Access on a need-to-know basis is one of the five Cyber Essentials controls and a core part of UK GDPR's security requirement. It also makes life simpler when someone leaves: one account switched off removes their access everywhere.

Ways to control access

Role-based access

Permissions given by job role, so a new starter gets the right access on day one.

Folder and file permissions

SharePoint, OneDrive and file shares set so each team sees its own data.

Device restrictions

Certain data only reachable from company devices.

Network separation

Sensitive systems kept on a separate part of the network.

Two-factor sign-in

A stolen password alone is not enough to get in.

Regular reviews

Access checked and updated as people change roles or leave.

Person signing in to a laptop while a phone shows multi-factor authentication

Setting access levels

Start by knowing what kinds of data you hold and how sensitive each is (see data classification). Then decide which roles need which data, and set permissions to match. We set this up in Microsoft 365 and your file storage, and review it regularly as people join, move and leave.

Subject access requests

Anyone whose personal data you hold, including clients, suppliers and staff, can ask for a copy of it. This is a subject access request, and you usually have one month to respond, in a clear and accessible format. Good access control and well-organised data make that much easier.

Questions we're asked

What is role-based access control?

Giving people access to data according to their job role, rather than person by person, so permissions are consistent and easy to change.

How long do we have to answer a subject access request?

Usually one month from receiving it, extendable in some complex cases.

Want this done for your business?

We put these controls in place for small and medium businesses, and keep them there. Tell us how your business works.

Get a fixed price