Physical Security & Access Control

User Management Roles · Least Privilege · Provisioning Records

Access to the 1TEN compliance platform is itself a system that must be access-controlled. User Management enforces least-privilege through defined roles, creates the provisioning records that AC and IA domains require, and produces the user roster assessors examine to verify access is limited to authorized individuals.

AC & IA Domain requirements supported
Least privilege Role enforcement
Audit trail All access changes logged
The design principle behind this module
A compliance platform that doesn't enforce access controls on its own data is documenting a control it doesn't practice. 1TEN is an air-gapped, on-premises appliance. And the same AC and IA principles it helps you document for your broader environment are implemented in the platform itself. The User Management module is where that is demonstrated: role-based access, named accounts, provisioning records, and an access history that assessors can review directly.

Role-Based Access and Least Privilege

1TEN supports defined roles that enforce least privilege: Administrator (full platform access including user management), Assessor (read/write access to all compliance modules), and Contributor (read/write access to assigned modules only). Each role grants the minimum access needed for the function it supports. No role has access to capabilities it doesn't need.

The user roster with role assignments is directly accessible for assessor review. When an assessor examines AC.L2-3.1.5 (least privilege), the platform produces the evidence directly: a named list of users, their assigned roles, the access those roles grant, and the date each assignment was made. The evidence is in the system, not in a separate document that needs to be updated manually.

Dashboard Requirements Evidence POA&M Reports
1TEN user profile showing role, granular permissions, and access history

Provisioning Records and Access History

Every account creation, role assignment, role change, and account deactivation is recorded in the Activity Log with timestamp, acting administrator, and the change made. This creates the account management documentation that AC.L2-3.1.1 (limit system access to authorized users) and IA.L2-3.5.1 (identify system users) require. Not as a separate record kept elsewhere, but as an automatic output of the platform's operation.

The access history demonstrates that access is actively managed: accounts are deactivated when personnel depart, roles are adjusted when responsibilities change, and no accounts persist beyond their authorization period. That active management is what assessors look for when distinguishing a real access control program from a policy that describes one.

Dashboard Requirements Evidence POA&M Reports
1TEN access review interface for periodic verification of user access

What You See Inside

  • *User roster with name, role, status, and account creation date. The list assessors examine for AC.L2-3.1.1
  • *Built-in roles: Administrator, Assessor, and Contributor. Each enforcing the minimum access required for that function
  • *Custom role definition. Create organization-specific roles with granular module-level permissions
  • *Account provisioning workflow. New accounts require administrator approval and role assignment before activation
  • *Account deactivation. Immediate access removal on termination or role change, with deactivation date recorded
  • *Full access history per user. Every role assignment and change with timestamp and acting administrator
  • *Training module integration. Role assignments drive training course requirements automatically
  • *Activity Log integration. All access changes captured in the tamper-evident audit trail

Built-In Roles and Access Levels

Role Access Level Typical Assignment
AdministratorFull platform access including user management, system settings, and all modulesISSO, compliance program owner, IT administrator
AssessorRead/write access to all compliance modules; no user management or system settingsCompliance lead, security analyst, C3PAO pre-assessment support
ContributorRead/write access to assigned modules only; no cross-module visibility beyond assignmentDomain owners, department-level contributors, IT staff assigned specific areas
Read-OnlyView-only access to assigned modules; no creation or modification of recordsLeadership review, audit support, read-only C3PAO pre-assessment access
CustomAdministrator-defined combination of module permissionsOrganization-specific role structures not covered by standard roles

What this replaces

  • *Shared credentials for the compliance platform. Multiple people using the same login with no individual accountability
  • *No access provisioning records. Accounts were created informally with no approval workflow or documentation trail
  • *Former employee accounts still active in the compliance platform after departure. No deactivation record, no accountability
  • *All users with administrator-level access regardless of function. No role differentiation, no least privilege enforcement
  • *Access control documentation maintained in a separate spreadsheet that doesn't reflect actual platform access

Practices Satisfied

Practice IDDescription
AC.L2-3.1.1 Limit system access to authorized users, processes acting on behalf of authorized users, and devices (including other systems).
AC.L2-3.1.5 Employ the principle of least privilege, including for specific security functions and privileged accounts.
IA.L2-3.5.1 Identify system users, processes acting on behalf of users, and devices.
IA.L2-3.5.3 Use multifactor authentication for local and network access to privileged accounts and for network access to non-privileged accounts.

Related Modules

Activity Log
Every account change is captured in the Activity Log. Provisioning, role changes, and deactivation are all part of the tamper-evident access history.
Training
Role assignments in User Management drive training course requirements. When a role changes, training requirements update automatically.
Registered Visitors
Authorized visitor pre-registration draws from the user roster. Visitors entering the facility are matched against known personnel and approved guests.
Assessment Summary
The user roster and role structure are referenced in the AC domain section of the Assessment Summary. Access control posture visible alongside all other domain scores.
See User Management in action.

Every module ships on the 1TEN appliance. No configuration required. Schedule 30 minutes and see it running with your organization's data.

Request a demo