Access Management Policy
Who accesses what, how access is born, how it falls — preferably on its own — and the review that checks it all.
Version 1.0 — effective September 1, 2026.
1. Principles
- Every account is named. One person, one e-mail, one account — shared accounts do not exist in our systems, by construction.
- Each account reaches only what it needs. A customer account reaches only its own company's data; administrative operations require Paramétrica's team profile. This applies across the entire surface of the systems.
- Access that is no longer justified, falls — through the automatic mechanisms below and, as a last resort, through the twice-yearly review.
2. The access lifecycle
- It is born with the registration and the acceptance of the terms, recorded with version and timestamp.
- It falls on its own when a person leaves the customer's records: the periodic synchronization with the installation drops the portal account and its open sessions, without depending on anyone remembering to tell us — and access does not return without a human act.
- It falls on the spot by administrator decision: immediate session revocation, and a password change drops that user's sessions.
- When the contract ends, access is blocked and personal data follow the lifecycle described in the Privacy Policy.
3. Accounts that are not people
There is a single service account, with a single purpose (automated e-mail delivery), identified and inventoried. Generic accounts for human use are forbidden by this policy. Test accounts live in a reserved range, outside real use.
4. Twice-yearly review
Twice a year, management reviews: team accounts and profiles against the actual staff and each person's role; customer accounts per installation, supported by the accounts and levels report the system provides; and the service account. The result is recorded as a tracked ticket, with number and date — a review with no findings is recorded too: absence is information.
Version 1.0 — September 1, 2026.