Security and access control

Give each user the contract access and authority their responsibility requires.

PactKeeper supports governed user setup, privileges, domains, groups, hierarchies, portfolio scope, and activity review so organizations can separate routine viewing from sensitive administration and contractual authority. Security is designed around least privilege, accountability, and the realities of distributed contract ownership.

Selected schools, universities, and organizations working with White Mountain Technologies.

  • Liwa University
  • Abu Dhabi University
  • Mohamed Bin Zayed University for Humanities
  • Al-Bayan Bilingual School
  • A'Takamul International School
  • Nouria

Overview

Contract access must reflect both responsibility and sensitivity

Contract records may contain commercial values, legal terms, property information, personal contacts, insurance details, site photographs, inspection findings, supplier information, and strategic decisions. Not every user should see every contract, and permission to view an agreement should not automatically grant authority to change dates, close alerts, upload governing documents, modify privileges, or approve decisions.

PactKeeper can organize users by roles, privileges, domains, groups, communities, hierarchies, locations, contract types, portfolios, or other approved scopes. The implementation defines which users can view, create, edit, administer, assign, complete, report, export, or configure each type of record. User information should be limited to what the contract operation actually requires and protected according to privacy and security policy.

Accountability also requires traceability. Authorized activity, record changes, alert completion, document additions, access administration, and other important operations should be reviewable according to the deployed capability and retention policy. Security configuration must be tested whenever roles, hierarchies, locations, integrations, or responsibilities change. User profiles should retain only the identity, work, position, location, and operational information required for the approved contract-management purpose.

Connected process

Manage access from request through review and removal

Access control is an ongoing lifecycle, not a one-time account setup.

  1. 01

    Request and justify access

    Identify the user, role, contract responsibility, portfolio, location, required actions, sensitive information, approver, and duration of access.

  2. 02

    Verify identity and source

    Confirm the account through the approved identity, HR, directory, or administrative process and avoid duplicate or shared identities.

  3. 03

    Assign least privilege

    Grant only the view, create, edit, complete, administer, report, export, or configuration permissions required for the approved scope.

  4. 04

    Test practical scenarios

    Validate permitted and prohibited contracts, documents, values, sites, alerts, dashboards, exports, administrative functions, and mobile or remote access.

  5. 05

    Review and monitor

    Perform periodic access review, examine privileged changes and relevant activity, and investigate stale, excessive, unused, or conflicting authority.

  6. 06

    Change or remove access

    Update permissions promptly after transfer, role change, location change, leave, external engagement end, or termination while retaining required audit history.

Capabilities

Security controls for distributed contract responsibility

The access model should support operational work while protecting sensitive agreements and administrative authority.

Named users and profiles

Maintain approved user identities, contact and work context, status, position, location, and only the additional information required for operations.

Roles and privileges

Separate viewing, editing, assigning, completing, reporting, exporting, security administration, configuration, and other sensitive functions.

Domains, groups, and communities

Organize users for portfolios, projects, departments, locations, special responsibilities, shared access, communication, or temporary assignments.

Hierarchy and location scope

Limit contract, site, stakeholder, document, alert, and dashboard visibility using approved organizational or geographic structures.

Privileged administration

Restrict user setup, role changes, alert definitions, configuration, data migration, report administration, and access-sensitive maintenance.

Activity and review

Support review of relevant user operations, changes, alert actions, administrative events, and access decisions according to deployed audit capability.

Governance

Apply least privilege, separation of duties, and periodic review

Security depends on controlled administration and repeatable governance as much as software settings.

Role ownership

Assign business and technical owners for each role, privilege, domain, group, hierarchy, portfolio, and administrative function.

Segregation of duties

Identify conflicting abilities such as changing contract dates and closing the resulting alert, or administering access and approving the same access.

Access review

Review active, inactive, privileged, external, temporary, transferred, and exception access on a documented schedule.

Incident and evidence handling

Define monitoring, investigation, escalation, preservation, notification, remediation, and retention for suspicious or unauthorized activity.

Implementation readiness

Design access using real responsibilities and sensitive records

Generic roles such as “user” and “administrator” are rarely sufficient for a mature contract operation.

01

Inventory users and responsibilities

Identify contract owners, reviewers, managers, site teams, finance, legal, procurement, inspectors, executives, administrators, and external participants.

02

Classify information and actions

Determine which contracts, values, documents, sites, inspections, reports, exports, and administrative functions require restricted access.

03

Build the role and scope matrix

Map each responsibility to view, create, edit, assign, complete, report, export, configure, and administer privileges by approved scope.

04

Test positive and negative access

Confirm that users can complete required work and cannot access prohibited contracts, documents, portfolios, or administrative actions.

05

Establish review and change control

Define provisioning, approval, periodic review, transfer, temporary access, emergency access, revocation, monitoring, and evidence retention.

Operational value

Controlled collaboration without unrestricted visibility

A well-designed access model allows distributed teams to manage contracts while preserving confidentiality and accountability.

Appropriate visibility

Users see the contracts, sites, documents, alerts, and reports required for their responsibilities—not the entire repository by default.

Protected authority

Sensitive configuration, access administration, date changes, alert closure, exports, and portfolio management remain with approved roles.

Reviewable accountability

Access decisions and relevant operational activity can be examined when investigating changes, exceptions, or control effectiveness.

Frequently asked questions

Questions about security and access control

Can different departments manage different contract portfolios?

Yes. Roles and scope can be configured by department, location, hierarchy, domain, group, contract family, portfolio, or responsible unit.

Can a user view a contract without being able to edit it?

Yes. View, create, edit, complete, report, export, administer, and configuration privileges can be separated according to the approved role model.

Can document access be more restricted than contract access?

Yes. Sensitive documents or document families can require narrower privileges than the related contract summary, depending on the configured security model.

Can temporary or external users be supported?

Yes, where approved. Their access should have a clear sponsor, purpose, scope, duration, review date, restrictions, and prompt revocation when no longer required.

Can access follow organizational or geographic hierarchies?

Yes. Reliable hierarchy and location data can support portfolio visibility, ownership, reporting, and escalation within the approved implementation.

Does PactKeeper replace organizational security governance?

No. The platform enforces configured access, but the organization remains responsible for identity assurance, approvals, role design, periodic review, incident response, privacy, and policy.

Plan the next step

Design contract access around responsibility, confidentiality, and accountability.

Review your users, roles, portfolios, hierarchies, documents, privileged functions, segregation rules, identity sources, audit needs, and access-review process with WMT.