Personnel, accessand lifecycle.
Who can reach your site, what they agree to first, how access is limited, and what happens the day someone leaves.
Who this covers
Everyone with access to Kenii source code, Kenii vendor-side services, or credentials issued by an institution. That includes contractors, who are held to the same terms.
Before access is granted
- A signed agreement covering confidentiality, acceptable use, and ownership of work.
- A written statement of what the person may access and why.
- Review of this policy, the security policy, and the privacy policy.
Kenii does not currently run formal multi-state background screening. Where an institution requires it for personnel touching its environment, Kenii will arrange screening for the named individuals as a condition of that contract.
Access rules
- Access is granted to the least a person needs to do the work, and is time-bound where the work is time-bound.
- Institutional credentials are issued by the institution, never shared between people, and never reused across institutions.
- Multi-factor authentication is required on every account that supports it, including version control, hosting, and email.
- Credentials are stored in a password manager, never in code, documents, issues or chat.
When someone leaves
Same day, before the departure is announced:
- Remove version control access and any deploy rights.
- Revoke Kenii service accounts and email.
- Notify every institution whose credentials that person held, and ask that they be revoked. Confirm revocation rather than assume it.
- Recover or wipe company devices.
- Rotate any shared credential that person could have seen.
- Record the date each step completed.
Step 3 is the one that reaches outside Kenii, and it is the one that gets confirmed in writing.
Privileged access review
A twice-yearly review of privileged access is defined and scheduled: every account on every vendor-side service, every institutional credential held, and every version control collaborator. Anything without a current reason is removed, and each review is recorded with a date and a reviewer.
The first scheduled review has not yet been carried out. Kenii will not claim a completed review before one has happened, and this page will name the date once it has.
Security awareness training
Security awareness training is defined and scheduled for everyone with access, on joining and annually. It covers phishing, credential handling, safe handling of institutional data, and how to report an incident.
This training is not yet running, and no completion has been recorded. Kenii states that plainly rather than answering a questionnaire as though the control were already operating.
Need screening foryour contract?
Background screening is arranged for named individuals as a condition of a contract that requires it. Ask and we will tell you what we can meet.