Blog / Product
Governance and access control for multi-project orgs
James Rourke ·
Governance in a multi-project organisation means three things: who can see what, who can change what, and who can prove it later. Get those right and most compliance requests become a report rather than a project.
Model permissions on teams, not people
Person-level permissions are the reason access reviews are painful. Every exception you grant becomes something a future admin has to interpret without context.
Assign access to a team, put people in teams, and let membership do the work. Someone changing role becomes a one-line change rather than an audit.
What auditors actually ask for
In our experience, four things, repeatedly:
- A current list of who has access to production data and why.
- Evidence that access is reviewed on a schedule.
- A log showing who changed permissions, and when.
- A documented offboarding process with proof it was followed.
Keep the audit trail queryable
An audit log you cannot filter is a liability — it proves you collected the data and could not answer the question. Make sure yours can be filtered by actor, resource, and date range before you need it to be.