FORM AWT-1 · AGENT CHECK SHEET · LIBRARY 1.0SCORER 1.0.0 · 8 PUBLIC SCENARIOS · SPECIMEN DATA
AI Agent Compliance Workflow Tester

Home / Rules / SOC 2 (Trust Services Criteria) / SOC 2 CC6.3 Role-based access, least privilege and segregation of duties

SOC 2 CC6.3 Role-based access, least privilege and segregation of duties

Rights over data, programs, functions and other protected assets is granted, changed or removed according to roles, responsibilities or system design and changes, applying least privilege and segregation of duties. Points of focus: access is created or modified on the asset owner's authorisation; it is removed when no longer needed; access structures (role-based, for example) limit privileges and separate incompatible functions; and roles and access rules are reviewed periodically for people who no longer need them (staff, contractors, vendors, partner personnel) and for system or service accounts that should not exist, and adjusted.

SOC 2 (Trust Services Criteria). Edition: 2017 Trust Services Criteria with revised points of focus (2022). Checked 2026-10-07. Our statement of the clause, cited; the standard is licensed and not quoted. Official source. The framework on compliance.theartofservice.com.

Steps that cite it

Evidence commonly asked for

Accepted citation forms are listed on the answer format page.