Access governance

Give people access to the work they need, and show why

A broad role can be useful, but it rarely tells the whole story. Pūnaha lets you control access to named resources and exact actions, then explain the roles, groups, assignments and denials behind the final decision.

Access with context

Move beyond one role for everything

Control can be specific without becoming impossible to manage.

Protect named resources

Set access for a particular workflow, case, knowledge store, model deployment, connection or other governed resource.

Choose the exact action

Separate actions such as viewing, changing, publishing, running and administering instead of treating access as all or nothing.

Work with people and services

Grant access to an individual, a local or external group, or a service identity used by another part of the platform.

Set a time boundary

Start access on a chosen date, let it expire automatically, or remove it when the work changes.

Use an explicit denial

A deny takes precedence when a person or service must not use a resource, even if another assignment would normally allow it.

See the effective result

Inspect the final access decision and the assignments that contributed to it before trying to diagnose a problem from the outside.

From request to review

Keep access understandable throughout its life

  1. Choose the resource and action

    Start with what the person or service needs to do, not with the broadest role available.

  2. Assign the appropriate subject

    Use a person, local group, external identity group or service identity that matches how the work will actually run.

  3. Check the effective access

    Review the complete result, including role access, grants, denials and time limits.

  4. Use and record the decision

    Apply the decision when the resource is opened or used, with the explanation available for investigation.

  5. Review it formally

    Ask the responsible reviewer to keep, change or remove access and retain an exportable record of the review.

Delegated administration

Let someone manage access without giving them the work itself

The person responsible for access does not always need permission to open or run the protected resource.

Pūnaha can separate the right to manage access from the right to use the resource. That makes it possible to give an access manager a focused responsibility without quietly widening their operational access.

The same principle supports formal reviews. A reviewer can see who has access, why they have it and whether it should remain, then record a keep, change or remove decision.

Separate responsibilities

Distinguish access administration from resource use.

Explain decisions

Show the role, group, grant, denial and timing behind effective access.

Retain review evidence

Export review results in CSV or JSON for the organisation's own assurance process.

What to evaluate

Ask the access questions that reflect real work

Access governance evaluation areas
QuestionWhat Pūnaha providesWhat your team decides
Who needs access?People, local groups, external groups and service identitiesThe appropriate subject and accountable owner
Access to what?Named resource types and individual resourcesThe scope needed for the work
What may they do?Exact resource actions and delegated administrationThe least access that remains practical
For how long?Immediate, scheduled and expiring assignmentsThe start, end and review timing
Why was it allowed or denied?An explainable effective-access decisionHow the evidence fits your assurance process

Access governance questions

Does a delegated access manager automatically get access to the resource?

No. The responsibility to manage access can be kept separate from permission to view, change or run the resource.

What happens when an allow and a deny both apply?

The explicit deny takes precedence. The effective-access view explains the assignments considered in the decision.

Can access be reviewed regularly?

Yes. A formal review can present current access for a keep, change or remove decision, with results available for export.

Does this page claim compliance with a particular standard?

No. Pūnaha provides access controls and review evidence. Each organisation still decides how those capabilities support its policies, assurance work and regulatory obligations.

Bring one access question that is difficult to answer today

We can follow it from the person or service to the protected resource, the final decision and the evidence available for review.