Authorization policy · Last updated August 18, 2026Questions? Contact DeskGate

Consent Is Not the Same as Authorization

Legal basis explains why personal data may be processed. Transparency explains the processing to affected people. Technical authorization controls which administrator or technician may use a DeskGate capability. These requirements work together but one does not replace another.

In employment relationships, consent may be invalid where refusal could cause disadvantage or where it cannot be withdrawn freely. Customers must determine the correct legal basis under applicable privacy, employment, communications, surveillance, and collective-labor rules. DeskGate does not make that determination for the customer.

Valid consent where used

A consent request should be separate from unrelated terms, written in clear language, specific about purpose and data, and supported by a genuine choice. Record when and how it was obtained and which notice applied. Provide a withdrawal route as easy as giving consent and stop consent-based processing when valid consent is withdrawn unless another lawful basis independently applies.

Administrator authorization

Assign named accounts and least-privilege roles. Do not share credentials or allow technicians to use capabilities simply because the interface makes them available. Review company and customer boundaries, device scope, connection rights, evidence access, export privileges, policy changes, and deployment authority regularly.

Remote support expectations

Tell users when interactive access may occur, what the technician can do, and whether a session is recorded or reported. Use visible approval where policy or law requires it. Unattended access should have a documented operational need, stronger controls, limited technicians, clear device scope, and periodic review.

Revocation and role change

Remove access promptly when employment, responsibility, customer assignment, or support need changes. Disable dormant accounts and recover managed devices or credentials. A revocation process should cover active sessions, setup packages, exported records, API or database access, local copies, and continuing confidentiality obligations.

Customer Responsibility

Customers are responsible for providing notices, obtaining valid consent where consent is chosen and legally appropriate, documenting alternative legal bases, configuring permission, responding to objections or withdrawals, and preventing unauthorized monitoring or remote access. DeskGate product controls assist implementation but cannot replace management approval, workforce communication, or legal analysis.

Contact DeskGate

Authorization Records and Control Testing

Maintain an authorization register identifying each privileged user, employer or customer, assigned role, permitted companies and groups, approved functions, approving owner, effective date, review date, and revocation date. High-impact capabilities such as hidden or unattended access, keyboard evidence, file collection, commands, scripts, software deployment, exports, blocking, and USB restrictions should receive separate consideration rather than being bundled into a generic administrator role.

Test permission with representative accounts. A manager should not automatically receive technical support powers, and a support technician should not automatically receive workforce evidence or customer-wide reports. Service providers must keep customer environments separated and confirm the correct customer and device before connection. Temporary access should expire automatically where possible or be removed immediately after the task.

If consent is relied upon, keep the consent text, language, version, timestamp, method, identity, and withdrawal history. Do not make an unrelated benefit conditional on optional monitoring. If processing continues after withdrawal under another lawful basis, explain that basis and its scope instead of pretending withdrawal has no effect. Complaints and objections should reach an impartial reviewer. Regular audits should compare approval records, product roles, actual use, support reports, leavers, transferred employees, and customer assignments.

Authorization must remain understandable to the person granting it and the technician using it. Avoid vague labels such as full access without an accompanying explanation of screen control, files, commands, scripts, deployment, recording, or unattended operation. Confirm renewed authority when the purpose, device owner, customer relationship, or technical scope changes materially.