Control Packs · IDN-004 · v1.0.0
Access Rights and Authorization Boundary
State who may perform which operations, enforce it where the action happens rather than only in the interface, remove access deliberately rather than by habit, and record every change to who holds what.
Status: review · Review: not independent. This is design guidance; review status does not establish independent verification or compliance.
What this safeguard addresses
Ensure the operations that carry authority have a stated set of who may perform them, that the check happens where the action is executed, that grants can be scoped and expired, and that every change to access is recorded.
- Who may do what is never written down, so everyone can do everythingRoles are implied by the interface rather than stated and checked at the point of action. Access is granted on request and never removed, temporary access has no expiry, privileged operations need no second person, and changes to who holds what access are not recorded — so nobody can say what the effective permission set currently is.
Versioned applicability rule
{
"characteristic": "PRIVILEGED_ACTION",
"equals": true
}Decisions for the project owner
Leave a decision open when its value is unknown. Suggested values become confirmed only through an explicit user decision.
- Which roles may perform which privileged operations, and which are they explicitly not allowed to perform?The system cannot infer your authority model. Naming the operations and who may perform each one is what makes an enforcement point implementable rather than a guess about intent.IDN-004-Q1 · scope
- How does access end when it is no longer needed?Access that is only ever granted accumulates. Whether it expires on a clock, on an offboarding event, or at a periodic review is a business decision with materially different implementations.IDN-004-Q2 · choice
Requirements for the coding agent
- IDN-004-R1Enforce the confirmed role-to-operation mapping at the point the operation executes, not only in the user interface or client. Deny by default for operations not granted, and do not rely on an unguessable route, a hidden control, or client-side state as the authorization boundary.
- IDN-004-R2Implement the confirmed way access ends, record every grant, change, and removal with who made it and when, and make the current holders of each privileged operation answerable from that record.
Tests and evidence to retain
- AUTHORIZATION_BOUNDARY_TESTAttempt each privileged operation as a role that is not granted it, including by calling the underlying route directly rather than through the interface, and confirm denial and a recorded decision.
- ACCESS_LIFECYCLE_TESTGrant temporary access, trigger the confirmed ending condition, and confirm the access no longer works and that the grant, change, and removal are each recorded.
- configuration_or_policy
- implementation_location
- test_result
- telemetry_definition
- operational_procedure
Passing a published example shows that example's behavior. A coding agent's implementation report remains a claim until its evidence is independently checked.
Related guidance
- AC-3 · Access EnforcementNIST_SP_800_53_5_2_0 · partially addressesEnforcing a confirmed role-to-operation mapping where the action executes is access enforcement for these operations; it does not cover the full control family.
- AC-2 · Account ManagementNIST_SP_800_53_5_2_0 · partially addressesA confirmed way access ends, with grants and removals recorded, addresses part of account management; it is not a complete account-management programme.
- AC-6 · Least PrivilegeNIST_SP_800_53_5_2_0 · informsNaming which roles may not perform an operation supports least privilege for this system; it does not establish least privilege across the organization.
- AU-2 · Event LoggingNIST_SP_800_53_5_2_0 · informsRecording authorization decisions and access changes supports later reconstruction of who could do what and when; it is not a complete audit programme.
Mappings indicate contextual relevance or partial support. They do not establish equivalence, certification, government endorsement, or complete framework implementation.
- National Institute of Standards and Technology — Security and Privacy Controls for Information Systems and OrganizationsGUIDANCE_LEAST_AUTHORITY
- National Institute of Standards and Technology — Security and Privacy Controls for Information Systems and OrganizationsGUIDANCE_AUDITABILITY
- National Institute of Standards and Technology — Security and Privacy Controls for Information Systems and OrganizationsGUIDANCE_NIST_SP_800_53_5_2_0