Employee Access Review Policy

Company: Payzario Inc. | Effective Date: April 2025 | Version: 1.0

1. Purpose

This policy establishes a process for periodically reviewing employee and contractor access to Payzario's systems and data to ensure access remains appropriate, necessary, and aligned with current job responsibilities.

2. Scope

This policy applies to all Payzario employees, contractors, and vendors who have been granted access to any Payzario system, platform, database, or third-party service account (including Plaid, Stripe, and cloud infrastructure).

3. Review Frequency

  • Monthly: Full review of all system access across all platforms.
  • Immediately: Upon any personnel change (hire, termination, role change, or contract end).

4. Monthly Access Review Checklist

Once per month, the admin must check each of the following and remove anyone who no longer needs access:

Base44 (App Platform)

  • Review all admin and user accounts in the Base44 dashboard
  • Remove any accounts not actively needed
  • Confirm only authorized admins have admin-level access

Stripe

  • Review all team members with Stripe dashboard access
  • Confirm API key holders are still active and authorized
  • Rotate any keys associated with departed personnel immediately

Plaid

  • Review access to the Plaid developer dashboard
  • Confirm API credentials are secured and not shared beyond authorized personnel
  • Rotate keys if any team member with access has left

Email & Domain

  • Review all active email accounts (e.g., support@payzario.com, admin@payzario.com)
  • Confirm domain registrar and DNS access is limited to authorized admins
  • Remove or disable any unused email accounts

5. Review Process

  1. Log into each platform and pull the current access list.
  2. Compare against the current active team roster.
  3. Remove anyone who no longer needs access.
  4. Document the review with date, findings, and any changes made.
  5. Sign off with admin approval and store the record.

6. Systems Covered

  • Base44 (app platform — admin and user accounts)
  • Plaid developer dashboard and API credentials
  • Stripe dashboard and API keys
  • Email accounts and domain registrar/DNS access
  • Cloud hosting and infrastructure accounts
  • Source code repositories

7. Access Revocation

Access must be revoked within 24 hours of an employee termination or role change. API keys shared with departing personnel must be rotated immediately. All revocations must be logged in the access review record.

8. Documentation

Each access review must be documented with the date, reviewer name, list of changes made, and admin sign-off. Records are retained for a minimum of 3 years.

9. Policy Review

This policy is reviewed annually or upon significant changes to team size, structure, or system access requirements.

Owner: Payzario Inc. | Contact: support@payzario.com