- Owner or Admin access to members, roles, and security evidence
- A current roster of people and their business responsibilities
- An owner for removing or reducing unnecessary access
- A review period and escalation path for exceptions
Review responsibility, not job title
Least privilege means a person has the minimum workspace and team-inbox authority needed for current tasks. It does not mean removing access first and repairing operations later. Map owned work before changing membership.
Quarterly review sequence
- Export or record the current Members view with Active, Invited, and Disabled filters.
- For every Owner and Admin, list the settings and approval duties that require elevation.
- Review restricted team-inbox membership and Manager, Member, or Viewer roles.
- Review automation owners, pending approvals, and people with lifecycle control.
- Review channel installers and operational owners in Connected apps.
- Review billing authority at the organization level.
- Identify stale invitations and people whose responsibility ended.
- Reassign open conversations, deals, tasks, follow-ups, automation ownership, inbox roles, and escalation duties.
- Demote or disable the membership.
- The Owner reviews Session logs and Recent changes for unexpected access activity.
| Change | Before the change | After the change |
|---|---|---|
| Admin to Member | Transfer settings, approval, and incident duties | Test required customer work and restricted inboxes |
| Disable Member | Reassign owned work and follow-ups | Confirm they cannot switch into the workspace |
| Remove inbox access | Move open queue work and views | Test visibility with another responsible member |
| Transfer ownership | Target is active, trained, MFA-enabled, and billing/security ready | Former Owner has the intended lower role |
| Remove connection operator | Assign provider and incident ownership; rotate provider access when needed | Run channel diagnostics |
Least-privilege layers
- 01AccountOrganization
The customer account and ownership boundary.
- 02ScopeWorkspace
The operating area where customer work and configuration live.
- 03GovernOwner
Controls the organization, subscription, and highest-risk access.
- 04ConfigureAdministrator
Configures members, channels, defaults, and operating controls.
- 05OperateMember
Works customer queues, records outcomes, and escalates exceptions.
Evidence to retain
Keep reviewer, review date, scope, decision, business owner, old/new access, and exceptions with an expiry date. Do not store password state, MFA secrets, raw session tokens, or unnecessary full IP data in a general access-review document.
Exception handling
Time-bound elevation needs a named approver, reason, start, expiry, and post-task review. WRKZY does not provide a universal temporary-role scheduler in the documented UI; track the expiry in an approved operational system and complete the change manually.
Detect privilege drift
Watch for multiple administrators without distinct duties, an Owner who is no longer active in operations, stale pending invitations, restricted inboxes with former members, private-mail dependencies, automations that only one person can explain, and provider accounts owned by a departed employee.
Recovery
If a change disrupts customer work, restore the narrow required grant—not blanket Admin—then document the missing dependency and update the checklist. For suspected unauthorized elevation, the Owner preserves member/change history and filters Session logs to the affected user/time before containment.
- Every elevated role has current duties
- Workspace and team-inbox grants reviewed separately
- Open work reassigned before removal
- Connection, automation, and billing ownership covered
- Exceptions have owners and expiry dates
- Owner reviewed security evidence for anomalies