Security, privacy, and billing · best practice

Run least-privilege access reviews

Review organization, workspace, inbox, automation, connection, and billing authority without orphaning customer work.

3 min readUpdated August 12, 2026
For
Owner, Admin
Availability
Your current plan and entitlements
Product evidence
WRKZY · reviewed August 12, 2026
Editorial review
WRKZY Editorial
Before you begin
  • Owner or Admin access to members, roles, and security evidence
  • A current roster of people and their business responsibilities
  • An owner for removing or reducing unnecessary access
  • A review period and escalation path for exceptions

Review responsibility, not job title

Least privilege means a person has the minimum workspace and team-inbox authority needed for current tasks. It does not mean removing access first and repairing operations later. Map owned work before changing membership.

Quarterly review sequence

  1. Export or record the current Members view with Active, Invited, and Disabled filters.
  2. For every Owner and Admin, list the settings and approval duties that require elevation.
  3. Review restricted team-inbox membership and Manager, Member, or Viewer roles.
  4. Review automation owners, pending approvals, and people with lifecycle control.
  5. Review channel installers and operational owners in Connected apps.
  6. Review billing authority at the organization level.
  7. Identify stale invitations and people whose responsibility ended.
  8. Reassign open conversations, deals, tasks, follow-ups, automation ownership, inbox roles, and escalation duties.
  9. Demote or disable the membership.
  10. The Owner reviews Session logs and Recent changes for unexpected access activity.
Access change order
ChangeBefore the changeAfter the change
Admin to MemberTransfer settings, approval, and incident dutiesTest required customer work and restricted inboxes
Disable MemberReassign owned work and follow-upsConfirm they cannot switch into the workspace
Remove inbox accessMove open queue work and viewsTest visibility with another responsible member
Transfer ownershipTarget is active, trained, MFA-enabled, and billing/security readyFormer Owner has the intended lower role
Remove connection operatorAssign provider and incident ownership; rotate provider access when neededRun channel diagnostics

Least-privilege layers

  1. 01
    AccountOrganization

    The customer account and ownership boundary.

  2. 02
    ScopeWorkspace

    The operating area where customer work and configuration live.

  3. 03
    GovernOwner

    Controls the organization, subscription, and highest-risk access.

  4. 04
    ConfigureAdministrator

    Configures members, channels, defaults, and operating controls.

  5. 05
    OperateMember

    Works customer queues, records outcomes, and escalates exceptions.

Review organization role, workspace role, restricted inbox membership, and feature-specific approvals as separate grants.

Evidence to retain

Keep reviewer, review date, scope, decision, business owner, old/new access, and exceptions with an expiry date. Do not store password state, MFA secrets, raw session tokens, or unnecessary full IP data in a general access-review document.

Exception handling

Time-bound elevation needs a named approver, reason, start, expiry, and post-task review. WRKZY does not provide a universal temporary-role scheduler in the documented UI; track the expiry in an approved operational system and complete the change manually.

Detect privilege drift

Watch for multiple administrators without distinct duties, an Owner who is no longer active in operations, stale pending invitations, restricted inboxes with former members, private-mail dependencies, automations that only one person can explain, and provider accounts owned by a departed employee.

Recovery

If a change disrupts customer work, restore the narrow required grant—not blanket Admin—then document the missing dependency and update the checklist. For suspected unauthorized elevation, the Owner preserves member/change history and filters Session logs to the affected user/time before containment.

Access review signed off
  • Every elevated role has current duties
  • Workspace and team-inbox grants reviewed separately
  • Open work reassigned before removal
  • Connection, automation, and billing ownership covered
  • Exceptions have owners and expiry dates
  • Owner reviewed security evidence for anomalies
Was this guide useful?

Choose an answer. No message text or personal information is collected.

Still need help?

Contact WRKZY support with the workspace name and a safe, redacted example.

Contact support about this guide