Skip to content
Timesheet Systems

All notes  /  06 · Operations

Reviewing Who Can See What

A quarterly review that reliably finds something, in a system holding a record of every employee's working day.

Procedure

Permissions in this category accumulate. People change roles, projects end, an integration account is created for a migration and never removed.

The review

Quarterly, twenty minutes.

List everyone holding each capability: record own time, approve, administer configuration, run the export, view reports, view individual detail, audit.

Check each against their current role.

Remove rather than deactivate, and record the review.

Report the result, including a clean one, which is what makes the control visible to the people it protects.

What it finds, consistently

People who changed role and kept the old team's visibility.

Contractors and implementation partners whose engagement ended.

Service accounts from a migration, still holding write access.

Administrators created for a project, with nobody remembering why.

Managers with organisation-wide visibility where team scope would do — usually because the product's default role was the only one configured.

Access logging

Reads matter as much as writes here. The question after any misuse is who looked at someone's record, and many products log only changes.

Check what the product logs during evaluation rather than after an incident.

Where reads are logged, sample the log as part of the quarterly review: does each access to individual detail map to a stated purpose?

Look for patterns: repeated access to one person, access outside working hours, a manager looking outside their team.

The manager default

Most products default a manager's view to full detail for their whole team, permanently.

A better default is aggregate and exceptions, with individual detail behind an action that records why.

This is a configuration choice, which means it is a decision someone made or failed to make.

Explain it to managers when you set it, because an unexplained restriction reads as distrust of them rather than as protection for everyone including them.

Integration accounts

Named service accounts, not a person's credentials. Integrations keyed to an employee break when that employee leaves, and it happens more than it should.

Scoped: a read-only extract should not hold write access.

Rotated, which requires the product to accept two valid credentials during a changeover.

Listed in the review alongside human accounts, because they are the ones nobody looks at.

What to report

Accounts by capability, with the change since last review.

Removals made.

Access log sample result.

Service accounts and their last use, where the product exposes it — an unused integration account is one to remove.

Explain the manager default

Without the reasoning, a limited view reads as distrust of the manager.

Say that the record is written by the person it describes, so its accuracy depends on their cooperation.

Say that a team who believe their daily pattern is read will record defensively.

Say that logged access protects the manager in any later accusation.

Most managers accept this readily once explained and resent it when the restriction arrives without a reason.

Access follows purpose

Visibility should match a documented management purpose. When assessing remote employee monitoring, test the smallest role that can perform each task and confirm what employees themselves can review.