Roles and rights
Access based on job function instead of full access. A salesperson has no reason to export the entire customer base in one go.
Business systems are usually well locked from the outside and wide open within. Ordinary users can see far more than their job requires, and the webshop integration runs on an admin account because that was quickest to configure. We tidy this up whether the system is Business Central, e-conomic, Uniconta or a bespoke CRM.
We treat each application both as a store of your data and as a channel through which that data can leave.
Access based on job function instead of full access. A salesperson has no reason to export the entire customer base in one go.
Every integration gets its own account or Entra ID app registration with exactly the permissions it uses.
Keys are moved out of config files into a key vault, restricted by IP address and rotated on a fixed plan.
We review which third-party apps users have allowed into your Microsoft 365 data and tighten the rules for new ones.
Who edited, who exported. Without a record there is nothing to investigate when something goes wrong.
A set routine for security updates, tested in a staging environment before they reach production.
The hardest part is rarely technical. It is agreeing who genuinely needs to see what.
Which applications are in use, by whom, what data they hold and where they send it.
Together with department heads we define the roles and what each one contains.
Roles go live, integrations move to their own accounts and logging is enabled.
Every six months rights are compared with job titles. People change roles internally and old access tends to follow them.
An integration running with admin rights is a gift to an attacker. All it takes is for the password to turn up in a config file or an old script, and the whole finance system is exposed. A separate account limited to the functions it really needs takes half an hour to set up.
Through department heads, not IT. They know what their people need to do the job. Two or three short meetings are usually enough, and the result is a spreadsheet you can keep up to date.
Block them on the day, but do not delete them straight away, as a deleted account takes its history with it. Blocking now and cleaning up after a month is the safer pattern.
We review configuration, permissions and integrations. A proper hunt for vulnerabilities in the code itself falls under penetration testing, which can be ordered separately.
The vendor patches the platform, but settings, users, integrations and add-ons you have bought are your responsibility. That is where we help keep order.
Tell us which systems you use. We will see who can view what and where integrations hold more rights than they need.
Thank you for getting in touch
One of our consultants already has it. Expect a reply within the working day; anything urgent goes straight to an engineer.
That city is not on our list. Check the spelling or pick the nearest larger town.