vStream Digital Media / ShineVR

Access Management process/procedure

Last updated: 03/02/25

Definitions

TermDefinition
Companymeans vStream Digital Media
ShineVRmeans the ShineVR product developed and operated by vStream Digital Media
GDPRmeans the General Data Protection Regulation
Responsible Personmeans Andrés Pitt, CTO
Access ControlSecurity mechanisms that regulate who can view or use resources in a computing environment
Identity and Access Management (IAM)Framework of policies and technologies ensuring the right individuals access the right resources at the right times for the right reasons
Principle of Least Privilege (POLP)Security principle whereby users are granted only the minimum access rights necessary to perform their job functions
Role-Based Access Control (RBAC)Method of restricting access based on the roles of individual users within an organisation
Multi-Factor Authentication (MFA)Authentication method requiring two or more verification factors to gain access to a resource
Privileged AccessSpecial access or abilities beyond those of ordinary users, typically administrative access
Service AccountSpecial account used by applications and services (not human users) to interact with systems

1. Policy Statement

vStream Digital Media is committed to protecting Company and ShineVR systems and data through comprehensive access control measures. All access to systems and data is granted based on legitimate business needs, the principle of least privilege, and appropriate role-based controls.

This policy establishes requirements for managing the complete lifecycle of access rights—from initial provisioning through ongoing monitoring to ultimate revocation—to ensure that only authorised individuals and services can access Company resources. All access is logged, monitored, and regularly reviewed to prevent unauthorised access and ensure compliance with data protection requirements.

2. Purpose

The purpose of this policy is to:

3. Scope

This policy applies to:

This policy covers the entire access lifecycle:

4. Principle Of Least Privilege (POLP)

4.1 Core Principle

Mandatory Requirement: All users, applications, and systems are granted only the minimum access rights necessary to perform their legitimate functions.

Application of POLP:

4.2 Need-to-Know Basis

Sensitive Data Access:

4.3 Separation of Duties

Critical Separations:

5. Role-Based Access Control (RBAC)

5.1 Standard Access Roles

The Company implements role-based access control with four standard roles:

5.1.1 User Role

Access Level: Limited, read-only or specific function access

Typical Permissions:

Examples:

Assignment Criteria:

5.1.2 Manager Role

Access Level: Moderate, read/write access to specific resources

Typical Permissions:

Examples:

Assignment Criteria:

5.1.3 Admin Role

Access Level: High, administrative access to specific systems or projects

Typical Permissions:

Examples:

Assignment Criteria:

5.1.4 SuperAdmin Role

Access Level: Full administrative access across all systems and projects

Typical Permissions:

Examples:

Assignment Criteria:

5.2 ShineVR Application Roles

Application-Level RBAC: In addition to infrastructure roles, ShineVR applications implement application-specific roles:

RolePermissionsUse Case
UserAccess own data, view assigned contentEnd users, trial participants
ManagerAccess team data, configure contentClinical supervisors, team leads
AdminConfigure application, manage users, view all dataApplication administrators
SuperAdminFull application control, system configurationCTO, designated application owner

Route-Level Access Control:

5.3 Role Assignment and Approval

Assignment Process:

  1. Request: User's manager or requester submits access request with business justification
  2. Review: CTO (or designated approver) reviews request for appropriateness
  3. Approval:
  1. Provisioning: IT/CTO provisions access per approved request
  2. Notification: User notified of access granted
  3. Documentation: Access recorded in access register

Required Documentation:

6. Google Cloud IAM (IDentity And Access Management)

6.1 Google Cloud IAM Framework

Primary Access Control Mechanism: All access to Google Cloud Platform resources controlled via Google Cloud IAM

IAM Components:

6.2 Google Cloud IAM Policies

Policy Structure:

Policy Management:

6.3 Google Cloud Roles

Predefined Roles Used:

Role Assignment Strategy:

6.4 Service Account Management

Service Accounts for Automated Access:

Service Account Security:

7. Authentication Requirements

7.1 User Authentication

Primary Authentication: Google Workspace Accounts

Authentication Standards:

7.2 Multi-Factor Authentication (MFA)

Mandatory MFA Requirements:

Must Use MFA:

Approved MFA Methods:

MFA Enrollment:

MFA Monitoring:

7.3 Service Account Authentication

API Keys and Service Credentials:

8. Access Provisioning

8.1 New User Onboarding

Access Provisioning Process:

Day 1 (Account Creation):

  1. Google Workspace account created by CTO or HR
  2. Initial password set and communicated securely
  3. User forced to change password on first login
  4. MFA enrollment required before system access
  5. Basic access granted (email, calendar, drive)

Week 1 (Role-Based Access):

  1. Manager submits access request for required systems
  2. CTO reviews and approves access request
  3. Access provisioned based on role assignment
  4. User added to appropriate Google Groups for resource access
  5. User notified of access granted

Onboarding Documentation:

8.2 Role Change or Transfer

Access Modification Process: When employee changes roles:

  1. Manager notifies CTO of role change
  2. Current access reviewed and documented
  3. New access requirements identified
  4. Unnecessary access revoked immediately
  5. New access provisioned based on new role
  6. Access change logged and documented

Systematic Review and Re-Certification:

8.3 Temporary or Elevated Access

Temporary Access Grants: For time-limited access needs (projects, consulting, audits):

Elevated Privilege Access: For tasks requiring temporary elevated privileges:

9. Access Monitoring And Logging

9.1 Access Logging

Comprehensive Logging:

Log Retention:

9.2 Access Monitoring

Automated Monitoring:

Alert Channels:

9.3 Automated Access Testing

Continuous Access Control Validation:

Access Test Examples:

10. Access Reviews And Re-Certification

10.1 Regular Access Reviews

Quarterly Access Review (Systematic): Conducted by CTO every quarter:

Annual Comprehensive Access Audit: Conducted annually:

10.2 Event-Driven Access Reviews

Immediate Review Triggers:

10.3 Manager Certification

Line Manager Responsibilities:

11. Access Revocation

11.1 User Departure

Immediate Actions (Same Day):

  1. Suspend Google Workspace account (within 2 hours of departure notification)
  2. Revoke Google Cloud Platform access (IAM policies)
  3. Disable service accounts specific to departing user
  4. Rotate credentials accessed by departing user (if applicable)
  5. Revoke application access (ShineVR admin accounts, etc.)
  6. Remove from Google Groups and mailing lists

Within 24 Hours:

  1. Transfer data ownership to manager (Google Drive, emails)
  2. Document all access revoked in user departure log
  3. Archive user data per data retention policy
  4. Collect company equipment (if applicable)
  5. Exit interview including return of credentials, keys, badges

Within 7 Days:

  1. Delete Google Workspace account (after data transferred)
  2. Remove from all external systems (Slack, GitHub, etc.)
  3. Update documentation removing user from team lists, contact lists
  4. Final access review confirming all access revoked

11.2 Contractor or Vendor Access Termination

End of Contract/Engagement:

11.3 Emergency Access Suspension

Immediate Suspension Scenarios:

Emergency Suspension Process:

  1. Immediate: Suspend Google Workspace account (within minutes)
  2. Within 1 hour: Revoke all system access
  3. Within 4 hours: Notify user and HR/management
  4. Within 24 hours: Document incident and rationale
  5. Ongoing: Review decision daily until investigation complete

12. Dormant And Inactive Accounts

12.1 Dormant Account Detection

Monitoring for Inactive Accounts:

12.2 Dormant Account Management

Dormant Account Process:

Exceptions:

Reactivation:

13. Privileged Access Management

13.1 Privileged Account Security

Enhanced Security for Privileged Accounts:

13.2 Privileged Access Monitoring

Enhanced Monitoring:

13.3 Emergency "Break Glass" Access

Emergency Access Procedures: For emergencies requiring immediate SuperAdmin access when CTO unavailable:

  1. Break glass account (emergency SuperAdmin) kept disabled
  2. Activation: Requires physical security key and CTO notification
  3. Logging: All break glass account activity logged separately
  4. Review: All break glass usage reviewed within 24 hours
  5. Deactivation: Account disabled immediately after emergency resolved

14. Wireless Network Access

14.1 Company Wireless Network Security

Wireless Security Standards:

Network Access Control:

Important Context:

15. Remote Access And Homeworking

15.1 Remote Access Security

Remote Work Access:

Remote Work Data Security:

15.2 Home Network Security

Employee Responsibilities:

16. Third-Party Access

16.1 Third-Party Access Policy

General Prohibition: Third parties do not have direct access to production environments except as detailed below.

Permitted Third-Party Access:

16.2 Third-Party Access Requirements

All third-party access must:

Third-Party Access Documentation:

17. Data Access Controls

17.1 Data Classification and Access

Access Based on Data Sensitivity:

ShineVR Data Access:

17.2 Database Access Controls

Cloud SQL Database Access:

17.3 Storage Access Controls

Cloud Storage Bucket Access:

18. Segregation Of Environments

18.1 Environment Separation

Mandatory Separation:

18.2 Environment-Specific Access

Access Restrictions:

18.3 Data Segregation

Production Data Protection:

19. Incident Response

19.1 Access-Related Incidents

Incidents Requiring Immediate Action:

Incident Response:

  1. Immediate: Suspend affected accounts
  2. Within 1 hour: Assess scope and impact
  3. Within 4 hours: Contain incident and prevent further access
  4. Within 24 hours: Investigate root cause
  5. Within 72 hours: Remediate and restore normal operations
  6. Within 1 week: Post-incident review and lessons learned

See Incident Response Plan for detailed procedures.

19.2 Compromised Credential Response

If credentials compromised:

  1. Immediate: Force password reset for affected user
  2. Immediate: Revoke all active sessions
  3. Within 1 hour: Rotate service account keys if applicable
  4. Within 4 hours: Review access logs for unauthorised activity
  5. Within 24 hours: Assess data exposure and breach notification requirements
  6. Ongoing: Enhanced monitoring for 30 days

20. Compliance And Audit

20.1 Access Control Compliance

Regulatory Compliance:

20.2 Access Audit Support

Audit Evidence:

Audit Procedures:

21. Roles And Responsibilities

RoleResponsibilities
CTO (Responsible Person)Overall access management policy ownership; approve Admin/SuperAdmin access; manage Google Cloud IAM; conduct quarterly access reviews; respond to access incidents; monitor privileged access; enforce POLP; audit access controls
Line ManagersRequest access for team members; certify access appropriateness; notify CTO of role changes; review team access annually; ensure departing staff access revoked; approve User/Manager access requests
IT AdministratorsProvision and revoke access per approvals; configure IAM policies; monitor access logs; respond to access incidents; maintain access documentation; assist with access reviews
All UsersProtect credentials; report suspected compromise; comply with access policies; use only authorised systems and data; report unusual access activity; complete security training

22. Training And Awareness

22.1 Access Management Training

Required Training:

Training Topics:

23. Exceptions

23.1 Exception Process

Exceptions to access management requirements may be requested for:

All exceptions must:

24. Policy Review And Updates

This policy will be reviewed:

25. Related Policies

This policy should be read in conjunction with:

26. Contact Information

For questions regarding this policy or to report access control incidents:

Data Protection Officer / CTO: Andrés Pitt Email: andres@vstream.ie Phone: (086) 788 6570