Access & User Management
Principles for user accounts, permissions and authentication
Authorised contact persons
At the start of our cooperation, you define who may request and approve which actions at Netstream. We distinguish between three roles:
| Role | Description |
|---|---|
| Super Admin | Full authorisation, including signing authority for the company |
| Admin | Main contact person with full authorisation within the service |
| User | Contact person with restricted rights within the service |
We record the assignment in a customer-specific authorisation matrix. Super Admins provide proof of their signing authority, for example with an extract from the commercial register or a written confirmation from the management.
User accounts
We create, change and delete user accounts only at the request of an authorised contact person. Accounts are personal. Shared or group accounts are only possible by explicit agreement.
A request contains at least the name, function, organisational unit, contact details, required permissions, start date and, for temporary accounts, the duration. We automatically deactivate temporary accounts when they expire.
Permissions
We grant access rights according to the principle of least privilege. Each person receives only the permissions they need for their tasks. We grant administration rights only to defined roles. We review any extension of rights before implementing it. If a request endangers security or compliance requirements, we can reject it or implement it only in part.
Departures and account locks
If a person leaves or changes role, request the deactivation without delay. We revoke the permissions and lock the account on the requested date. In urgent cases, for example in the event of dismissal without notice, we lock access in an expedited procedure. In the event of security incidents, we can also lock accounts on our own initiative and inform you immediately.
Passwords and authentication
The requirements for passwords depend on the platform concerned and on current security standards. Passwords are personal and confidential. They must not be shared or used for several systems. Wherever possible, we use two-factor authentication (2FA).Regular review
We review user accounts and permissions regularly. Before a recertification, we inform you, and you confirm which accounts and roles are still needed. We lock or remove accounts and rights that are no longer needed.