Authorization Records and Control Testing
Maintain an authorization register identifying each privileged user, employer or customer, assigned role, permitted companies and groups, approved functions, approving owner, effective date, review date, and revocation date. High-impact capabilities such as hidden or unattended access, keyboard evidence, file collection, commands, scripts, software deployment, exports, blocking, and USB restrictions should receive separate consideration rather than being bundled into a generic administrator role.
Test permission with representative accounts. A manager should not automatically receive technical support powers, and a support technician should not automatically receive workforce evidence or customer-wide reports. Service providers must keep customer environments separated and confirm the correct customer and device before connection. Temporary access should expire automatically where possible or be removed immediately after the task.
If consent is relied upon, keep the consent text, language, version, timestamp, method, identity, and withdrawal history. Do not make an unrelated benefit conditional on optional monitoring. If processing continues after withdrawal under another lawful basis, explain that basis and its scope instead of pretending withdrawal has no effect. Complaints and objections should reach an impartial reviewer. Regular audits should compare approval records, product roles, actual use, support reports, leavers, transferred employees, and customer assignments.