Skip to content
d3 Wiki
07.02

Access control and offboarding

People have the access they need, and no more, and it disappears when they leave.

Updated
Oct 3, 2026
On this page

Purpose

People have the access they need, and no more, and it disappears when they leave.

The standard

  • Least privilege. Roles by group, not by person: GitHub teams, Supabase org roles, Vercel members, wiki roles.

  • Access requests go through the onboarding checklist (00.02) or an issue; the system owner grants.

  • Quarterly access review by each system owner: list members, remove anyone who doesn't need it.

Offboarding checklist (same day)

  • Transfer ownership of tools/pages (00.05)

  • Remove from GitHub org, Vercel team, Supabase org, wiki, chat

  • Revoke Claude/Cursor seats and any API keys they created

  • Rotate shared secrets they could have seen (07.01)

  • Reassign Rhino/Revit licenses

  • Remove SSH keys / deploy keys tied to their machine

Owner: [TEAM] · Last reviewed: 2026-09