Access Control Policy
Version: 1.0 Last Updated: February 2026
1. Purpose
This policy defines how access to the Nova IAM platform itself is controlled, and how Nova IAM enforces access control for managed users and systems.
2. Platform Access Control
2.1 Authentication
- All users must authenticate with email and password
- Passwords are hashed using memory-hard algorithms (scrypt/pbkdf2) before storage
- No default accounts ship with production deployments
- Failed login attempts are logged with IP address for security monitoring
2.2 Session Management
- Sessions are server-side, bound to cryptographically signed cookies
- Session tokens are invalidated on logout
- The
SECRET_KEYused for signing must be unique per deployment
2.3 Administrative Access
- Administrative functions (user management, role assignment, system configuration) require authenticated access
- All administrative actions are recorded in the audit log with actor identity
3. Managed Access Control Model
3.1 Role-Based Access Control (RBAC)
Nova IAM implements a hierarchical RBAC model:
Org Unit (HR Structure)
|
+-- Business Roles (Composite)
|
+-- Entitlements (Individual permissions)
|
+-- Backend System Privileges (SAP roles, LDAP groups, Entra groups)
3.2 Assignment Types
| Type | Description | Removable By |
|---|---|---|
| Direct | Manually assigned entitlement | Administrator |
| Indirect | Inherited from a business role | Removing the business role |
| Business Role | Composite role assigned to user | Administrator |
| Org Unit | Business role propagated from organizational unit | Removing user from org unit or role from unit |
3.3 Inheritance Protection
- Inherited entitlements (indirect assignments) cannot be directly removed
- The UI disables removal controls for inherited entitlements
- The API rejects removal requests for indirect-only entitlements
- To remove an inherited entitlement, the parent business role must be unassigned
3.4 Provenance Tracking
Every assignment displays its origin:
- Entitlements show which business role(s) they are inherited from
- Business roles show which org unit(s) they are assigned from
- Backend system roles show their parent business role provenance
4. Least Privilege Principle
4.1 Time-Bound Access
- All role assignments support validity dates (
valid_from,valid_to) - Duration presets available: 6 months, 1 year, 3 years
- Expired assignments can be automatically cleaned up via scheduled jobs
4.2 Risk Scoring
- Every entitlement and business role has a risk score:
no_risk,low,medium,critical,not_scored - Risk scores are visible during assignment to inform decision-making
- AI analysis can flag anomalous or excessive access patterns
4.3 Segregation of Duties
- Business role composition is visible (member entitlements listed)
- Role overlap across business roles is detectable via the UI
- AI-powered SoD analysis available (when AI features are enabled)
5. Backend System Provisioning
5.1 Provisioning Control
- Auto-provisioning is controlled by a system-wide setting (disabled by default)
- When enabled, business role assignments trigger automatic provisioning to connected systems
- Provisioning is best-effort: failures are logged but do not block IAM state changes
5.2 Provisioning Methods
| System | Method | Approach |
|---|---|---|
| SAP | BAPI_USER_ACTGROUPS_ASSIGN | Full sync (complete desired state) |
| LDAP | Group membership modification | Incremental add/remove |
| Entra ID | Microsoft Graph API | Incremental add/remove |
5.3 Reconciliation
- Backend system state can be compared against Nova IAM desired state
- Discrepancies are flagged for review
- Reconciliation runs can be scheduled as background jobs
6. Access Review & Recertification
6.1 Workflow Support
- Approval workflows can be defined for access requests
- Multi-step approval chains with configurable approvers
- Approval decisions are recorded with actor, timestamp, and rationale
6.2 Access Request Process
- User or manager submits access request
- Request routed through configured approval workflow
- Each approver reviews and approves/rejects
- On full approval, roles are assigned automatically
- All steps audited
7. Account Lifecycle
| Phase | Action | Controls |
|---|---|---|
| Joiner | New user created | Org unit assignment propagates baseline business roles |
| Mover | Department/role change | Org unit reassignment updates business role inheritance |
| Leaver | User departure | Account deactivation, role revocation, backend deprovisioning |
Fragen zu diesem Dokument? Schreiben Sie an
trust@nova-iam.com –
wir bestätigen den Eingang innerhalb von 2 Werktagen.