# WiBiz Access Control and Identity Summary

**Version:** v1.0  
**Published:** 6 August 2026  
**Owner:** WiBiz Operations  
**Classification:** Public  
**Status:** Current public summary

## 1. Purpose

This summary describes the required access-control model for WiBiz corporate systems and client builds. The actual accounts, roles, authentication methods, review records, and provider exceptions are verified per system.

## 2. Control commitments

WiBiz requires:

- named access rather than shared administrator identities wherever the service supports it;
- least-privilege and role-based permissions appropriate to a person's work;
- approval before access is granted or materially changed;
- strong authentication and multi-factor authentication where supported;
- controlled service accounts, application credentials, secrets, and emergency access;
- separation of production and non-production access where the architecture supports it;
- prompt removal or adjustment of access after offboarding or role change;
- periodic review of privileged and general access;
- logging and review of sensitive administrative activity where supported.

## 3. Evidence boundary

An access claim requires a current account inventory, approval record, role or permission evidence, authentication evidence, review record, and exception status. A policy statement alone does not establish that a provider enforced a setting.

Where a service cannot support a required control, the limitation must be recorded with a risk decision, compensating control, owner, and expiry. WiBiz does not describe such a system as fully compliant with the required control.

## 4. Client-build application

The Build Security and Data Annex identifies:

- client, WiBiz, provider, and service-account roles;
- privileged access and support-access paths;
- single sign-on, multi-factor authentication, and session controls;
- tenant and client isolation;
- approvals, review cadence, logging, and emergency access;
- customer responsibilities and accepted exceptions.

## 5. Contact

Security enquiries: security@wibiz.ai

---

WiBiz Access Control and Identity Summary v1.0, 6 August 2026.
