Access Controls Policy
Share
This Access Controls Policy defines how Worklittle grants, manages, and revokes access to systems and data.
Purpose
Access controls ensure that only authorized individuals and services can reach Worklittle resources, and only to the extent required for their role or function.
Authentication requirements
Interactive access to Worklittle applications requires authenticated user accounts.
Programmatic access to the Worklittle API requires issued API keys or valid user sessions.
Shared or anonymous credentials are not used for production administrative access.
Authorization
Platform users access only the organization and data associated with their account.
Employer platform features are scoped to the signed-in organization context.
Administrative and operational access is limited to personnel with a documented business need.
Least privilege
Worklittle follows least-privilege principles. Access is granted at the minimum level needed to perform a job function and is removed when no longer required.
API keys
API keys are issued to authorized accounts and can be revoked at any time.
Keys are scoped to the account and organization that created them.
Keys must be stored securely and must not be embedded in public client code.
Session and account lifecycle
Inactive or compromised credentials are disabled or rotated.
Access tied to employment or contractor engagement is revoked when the engagement ends.
Access reviews
Worklittle periodically reviews access to production systems, administrative tools, and third-party integrations to confirm continued business need.
Questions
For access-related questions, contact contact@worklittle.com.
Author

Worklittle