Access is a living control
Security is not only login. In AWRA, access is shaped by roles, permissions, MFA, device trust, session control, plan entitlements, and sensitive action throttles.
A secure tenant is reviewed regularly. People change roles, devices get lost, vendors leave, and support access must be controlled. The access model must move with the business.
Access control layers
| Layer | Controls | Review question |
|---|---|---|
| Identity | Login, password reset, MFA | Is this person still who they claim to be? |
| Role | Permissions and least privilege | Can they do only their job? |
| Device | Trust, lock, unlock, revoke | Is this device still safe? |
| Session | Terminate user or device sessions | Should current access continue? |
| Support | Impersonation with audit | Was support access justified and recorded? |