Back to Compliance

RepLogix Access Control Policy

Effective Date: August 8, 2026

This Access Control Policy defines how RepLogix manages access to systems, applications, and data. It establishes the principles and procedures for granting, modifying, and revoking access to protect customer and organizational data.

1. Purpose and Scope

This policy applies to all RepLogix personnel, contractors, and third parties who require access to RepLogix systems or data. It covers both administrative access to infrastructure and user access to the RepLogix application.

2. Access Management Principles

  • Least Privilege: Access is granted at the minimum level necessary to perform assigned duties
  • Need-to-Know: Access to specific data is restricted to those with a legitimate business need
  • Separation of Duties: Critical functions require multiple individuals to prevent conflicts of interest or fraud
  • Accountability: All access is attributed to identifiable individuals — shared accounts are prohibited

3. Role-Based Access Control (RBAC)

RepLogix uses role-based access control to manage permissions within the application:

  • Developer: Full platform access for development, debugging, and administration
  • Admin (Account Admin): Manages their organization's roster, settings, team members, and billing
  • District Admin (DAC): District-level oversight across multiple campuses and teams
  • Campus Admin (CAC): Campus-level management across multiple team accounts
  • Account User (AU): Limited access to roster and check-in functions within their team
  • User: Standard coach access to their own team's data

Each role has defined permissions. Access escalation requires management approval.

4. Multi-Factor Authentication (MFA)

MFA is enforced for privileged and administrative access:

  • Developer and admin-level accounts are required to use MFA
  • MFA is enforced through the platform authentication provider (Google OAuth or email-based authentication with verification)
  • Service accounts and API keys are rotated periodically and stored in secure secret management
  • Recovery procedures require identity verification before MFA reset

5. Access Provisioning

New access is provisioned as follows:

  • Access requests are submitted and documented with business justification
  • Requests are approved by the user's manager or the Security Lead
  • Access is provisioned following least-privilege principles
  • Provisioning is logged for audit purposes

6. Access Modification and Revocation

  • Access is modified when a user's role or responsibilities change
  • Access is revoked within 24 hours of termination, resignation, or contract end
  • Temporary access (contractors, vendors) expires automatically at the end of the engagement
  • Revocation is verified by confirming account disablement and token invalidation

7. User-Access Reviews

Access rights are reviewed on a regular basis to ensure appropriateness:

  • Quarterly reviews of all privileged and administrative accounts
  • Annual reviews of all user access across systems and applications
  • Reviews verify that access aligns with current roles and responsibilities
  • Excessive or unnecessary access is revoked promptly
  • Review results are documented and retained for audit

8. Password Requirements

  • Passwords must meet minimum complexity requirements enforced by the authentication provider
  • Password reuse is discouraged; users are prompted to use unique credentials
  • Account lockout is enforced after repeated failed login attempts
  • OAuth-based authentication (Google) is supported to reduce password-based risk

9. Remote Access

  • Remote access to administrative systems requires MFA
  • Remote sessions are encrypted using TLS/HTTPS
  • Administrative access to production infrastructure is restricted to authorized personnel
  • Remote access activity is logged and monitored

10. Policy Review

This Access Control Policy is reviewed at least annually and updated when access models, systems, or organizational structure change significantly.

11. Contact

For questions about this policy, contact:

RepLogix Security

Email: RepLogixapp@gmail.com