Skip to content
English
  • There are no suggestions because the search field is empty.

Access & User Management

Principles for user accounts, permissions and authentication

Authorised contact persons

At the start of our cooperation, you define who may request and approve which actions at Netstream. We distinguish between three roles:

Role Description
Super Admin Full authorisation, including signing authority for the company
Admin Main contact person with full authorisation within the service
User Contact person with restricted rights within the service

We record the assignment in a customer-specific authorisation matrix. Super Admins provide proof of their signing authority, for example with an extract from the commercial register or a written confirmation from the management.

User accounts

We create, change and delete user accounts only at the request of an authorised contact person. Accounts are personal. Shared or group accounts are only possible by explicit agreement.

A request contains at least the name, function, organisational unit, contact details, required permissions, start date and, for temporary accounts, the duration. We automatically deactivate temporary accounts when they expire.

Permissions

We grant access rights according to the principle of least privilege. Each person receives only the permissions they need for their tasks. We grant administration rights only to defined roles. We review any extension of rights before implementing it. If a request endangers security or compliance requirements, we can reject it or implement it only in part.

Departures and account locks

If a person leaves or changes role, request the deactivation without delay. We revoke the permissions and lock the account on the requested date. In urgent cases, for example in the event of dismissal without notice, we lock access in an expedited procedure. In the event of security incidents, we can also lock accounts on our own initiative and inform you immediately.

Passwords and authentication

The requirements for passwords depend on the platform concerned and on current security standards. Passwords are personal and confidential. They must not be shared or used for several systems. Wherever possible, we use two-factor authentication (2FA).

Regular review

We review user accounts and permissions regularly. Before a recertification, we inform you, and you confirm which accounts and roles are still needed. We lock or remove accounts and rights that are no longer needed.