Access Controls Policy
Owner: FinArctic Operations and Fluent Terrain Security and Engineering. Effective and last updated: July 21, 2026.
This policy documents how GlacialBooks limits access to production assets, sensitive financial data, and internal support tooling through centralized identity, role-based access, verified identity, workforce MFA, tenant isolation, audit logs, and managed identities.
Centralized identity
Customer sign in is governed through Clerk, while workforce and service access use Microsoft Entra ID. Legacy local-password sign in is disabled in deployed environments. Identity-provider sessions are validated on every protected request and organization membership is rechecked against current records.
Identity verification and MFA
A verified email is required before Plaid Link or another financial-account connection flow is offered. MFA is required for workforce access to production systems that store or process customer financial data. Additional customer MFA is coming soon and will be described here when it is enforced.
Role based access control
GlacialBooks organization roles are Owner, Admin, Accountant, Staff, and Read Only. The service enforces the minimum role required for each protected action. Internal support roles are separate from customer organization roles and require internal identity validation.
Least privilege
Production access requires a documented business need and an appropriately scoped role. Privileged support access, integration management, role changes, exports, and account deletion are logged. The application uses a dedicated database login that cannot bypass row-level security, alter migration state, or modify or delete audit records.
Access reviews
Privileged production access, internal support access, managed identities, service principals, and app-role assignments require periodic owner review. Access for terminated workers must be removed within 24 hours. Access changed by role transfer must be updated within 1 business day.
Zero trust operating model
Access is deny by default. Requests must authenticate, authorize against current tenant membership, and satisfy role checks. Tenant database access uses forced row-level security with a signed organization context. Production data services use private networking, explicit role assignments, managed identities, and server-side secret storage.
Non human access
Automation and production workloads use service-level identities where available. Provider integrations use secure provider-authorized connection flows, signed inbound events, encrypted transport, and server-side credential storage. Static client secrets require an owner, restricted storage, and a 90-day review.
Sensitive data safeguards
Sensitive financial data is visible only through authorized tenant-scoped routes. Source evidence, payroll employee details, support actions, admin views, and export functions are restricted by role and audited. Tenant-scoped access is enforced server side.
See the account authentication page for the controls used before financial account connection flows.