Access Controls Policy

Share

This Access Controls Policy defines how Worklittle grants, manages, and revokes access to systems and data.

Purpose

Access controls ensure that only authorized individuals and services can reach Worklittle resources, and only to the extent required for their role or function.

Authentication requirements

  • Interactive access to Worklittle applications requires authenticated user accounts.

  • Programmatic access to the Worklittle API requires issued API keys or valid user sessions.

  • Shared or anonymous credentials are not used for production administrative access.

Authorization

  • Platform users access only the organization and data associated with their account.

  • Employer platform features are scoped to the signed-in organization context.

  • Administrative and operational access is limited to personnel with a documented business need.

Least privilege

Worklittle follows least-privilege principles. Access is granted at the minimum level needed to perform a job function and is removed when no longer required.

API keys

  • API keys are issued to authorized accounts and can be revoked at any time.

  • Keys are scoped to the account and organization that created them.

  • Keys must be stored securely and must not be embedded in public client code.

Session and account lifecycle

  • Inactive or compromised credentials are disabled or rotated.

  • Access tied to employment or contractor engagement is revoked when the engagement ends.

Access reviews

Worklittle periodically reviews access to production systems, administrative tools, and third-party integrations to confirm continued business need.

Questions

For access-related questions, contact contact@worklittle.com.

Author

Worklittle