Employee Access Review Policy
Company: Payzario Inc. | Effective Date: April 2025 | Version: 1.0
1. Purpose
This policy establishes a process for periodically reviewing employee and contractor access to Payzario's systems and data to ensure access remains appropriate, necessary, and aligned with current job responsibilities.
2. Scope
This policy applies to all Payzario employees, contractors, and vendors who have been granted access to any Payzario system, platform, database, or third-party service account (including Plaid, Stripe, and cloud infrastructure).
3. Review Frequency
- Monthly: Full review of all system access across all platforms.
- Immediately: Upon any personnel change (hire, termination, role change, or contract end).
4. Monthly Access Review Checklist
Once per month, the admin must check each of the following and remove anyone who no longer needs access:
Base44 (App Platform)
- Review all admin and user accounts in the Base44 dashboard
- Remove any accounts not actively needed
- Confirm only authorized admins have admin-level access
Stripe
- Review all team members with Stripe dashboard access
- Confirm API key holders are still active and authorized
- Rotate any keys associated with departed personnel immediately
Plaid
- Review access to the Plaid developer dashboard
- Confirm API credentials are secured and not shared beyond authorized personnel
- Rotate keys if any team member with access has left
Email & Domain
- Review all active email accounts (e.g., support@payzario.com, admin@payzario.com)
- Confirm domain registrar and DNS access is limited to authorized admins
- Remove or disable any unused email accounts
5. Review Process
- Log into each platform and pull the current access list.
- Compare against the current active team roster.
- Remove anyone who no longer needs access.
- Document the review with date, findings, and any changes made.
- Sign off with admin approval and store the record.
6. Systems Covered
- Base44 (app platform — admin and user accounts)
- Plaid developer dashboard and API credentials
- Stripe dashboard and API keys
- Email accounts and domain registrar/DNS access
- Cloud hosting and infrastructure accounts
- Source code repositories
7. Access Revocation
Access must be revoked within 24 hours of an employee termination or role change. API keys shared with departing personnel must be rotated immediately. All revocations must be logged in the access review record.
8. Documentation
Each access review must be documented with the date, reviewer name, list of changes made, and admin sign-off. Records are retained for a minimum of 3 years.
9. Policy Review
This policy is reviewed annually or upon significant changes to team size, structure, or system access requirements.
Owner: Payzario Inc. | Contact: support@payzario.com