Least-privilege access
We define required permissions, approval owners, access duration, and removal responsibilities for the work in scope.
Access, data-handling, and review requirements form the baseline for each engagement. The technical controls used to meet them depend on the platform, configuration, and agreed scope.
We define required permissions, approval owners, access duration, and removal responsibilities for the work in scope.
We define data-handling requirements, including encryption in transit and at rest. Implementation depends on the systems and configurations in scope.
Isolation requirements are defined around the work and data involved. Account, network, and storage separation depend on the platform and configuration.
Logging, monitoring, and alerts are scoped to the engagement and platform capabilities, with review responsibilities documented.
Sensitive actions require human approval where specified in the agreed workflow. Review requirements and responsibilities are documented.
Synotech leads security decisions and communication, with client approval for relevant changes according to their type and scope.
Permitted records
Required fields
Approved sources
Validate inputs
Route exceptions
Request required approval
Proceed after checks
Update the target system
Record the outcome
Confirm the provider, configuration, and review requirements for each use case. The diagram illustrates a possible flow.
In this example, a payment to a new vendor is held for review because the amount exceeds the workflow’s approval threshold.
Display only — these controls do not initiate payments or change records.

Identify the workflows, systems, and operational responsibilities included in the engagement.
Identify the data involved, its sensitivity, and restrictions on its use or movement.
Review platform capabilities, connected services, and the permissions each connection requires.
We work with your team to identify relevant control requirements and agree the implementation scope.
For each requirement, agree the implementation owner, review authority, and scope before work begins.
Review responsibilities and data-handling requirements before the engagement begins.
Synotech leads access decisions, with client approval according to the type and scope of the change. Access requirements, duration, and removal responsibilities are documented for the engagement.
Synotech leads security decisions and incident communication. Relevant changes require client approval according to their type and scope. Responsibilities are documented for the engagement; any response commitments need to be agreed within that scope.
Your data belongs to you. When the engagement ends, Synotech returns your data to you. Data-handling requirements are documented for the engagement; confirm the retention period and deletion schedule for the records involved.
Confirm the exact provider, service, account settings, data sent, and applicable retention or training terms for the proposed workflow.
Ask to discuss the proposed access, data-handling, and review requirements, and confirm what supporting material is available for the engagement.
Discuss your access, data-handling, and review requirements alongside the work you need.
Start Free Health Check