All Policies

Employee Access Management Policy

Effective Date: April 23, 2026

1. Purpose

This policy establishes procedures for provisioning, modifying, and de-provisioning access to VaultKeeper systems when team members join, change roles, or leave the organization.

2. Access Provisioning (Onboarding)

When a new team member joins:

3. Systems Requiring Access Management

SystemAccess MethodDe-provisioning Method
GitHub RepositoryGitHub organization inviteRemove from organization
Firebase ConsoleGoogle account with IAM roleRemove IAM binding
Cloudflare DashboardTeam member inviteRemove team member
Plaid DashboardTeam member inviteRemove team member
Teller DashboardAccount credentialsReset credentials, revoke access

4. Access Modification (Role Change)

When a team member changes roles:

5. Access De-provisioning (Offboarding)

When a team member is terminated or leaves the organization, the following steps are completed within 24 hours:

6. Emergency De-provisioning

In cases of termination for cause or suspected security compromise:

7. Verification

After any de-provisioning event:

8. Automation

Where supported by the platform, automated de-provisioning is configured:

9. Policy Review

This policy is reviewed at least annually or when organizational changes occur.