- Home
- Policies & Security
- Access Control
Access Control
Policy regarding access control for internal systems.
This policy defines how access is requested, granted, and reviewed for all internal tools, cloud resources, and code repositories at Zoos Global.
Principles of Access Control
Section titled “Principles of Access Control”- Least Privilege: Users must only be granted the minimum level of access required to perform their specific job responsibilities.
- Need-to-Know: Access to data must be restricted to individuals whose roles require access to that specific information.
- Role-Based Access Control (RBAC): Permissions are assigned to pre-defined user roles rather than individuals.
Access Request Procedure
Section titled “Access Request Procedure”To request access to a resource:
- Open a request ticket in our internal IT portal.
- Specify the resource, the required role, and a brief justification for the access.
- The request must be approved by your manager and the resource owner.
Access Reviews
Section titled “Access Reviews”Access reviews are conducted quarterly by team leads and the security team. Any accounts showing inactivity for more than 90 days will be automatically deactivated.

