Map access to the work
We list the users, resources and actions before designing roles. Viewing logs, uploading a file and restarting a service can require different permissions. A customer support role should be limited to its assigned environment.
Access expiry, account removal and emergency administration are part of the model. The design includes how current sessions respond to a permission change.
Choose the records needed for review
An activity record can identify the actor, target, action, time and result. A full terminal recording captures a different level of detail and may include sensitive output. Retention, retrieval and redaction need separate decisions.
Teleport documents the distinction between audit events and terminal or desktop recordings. A custom build should state which evidence it collects and which events remain outside it.
Preserve a usable chain of evidence
Hashed or signed records can help detect changes to stored data. Key protection, log delivery and the handling of missing records determine what that evidence means. A signature alone does not establish that every possible action was recorded.
We test record ordering, verification failure and export permissions. A reviewer should see a gap or failed check instead of a reassuring success label.
Make the review process explicit
The delivery describes the retained events, storage location, access rules and recovery procedure. It includes tests for wrong targets and missing authority. Required regulatory or customer assessments are agreed with the responsible reviewer.
Before you begin
Do you provide compliance certification?
The development scope can implement controls and produce evidence for an assessment. Certification requires the appropriate independent process and agreed standard.
Can logs contain passwords or personal information?
They can. We define collection limits, redaction, retention and access before enabling detailed session capture.
DSDillon / 26 September 2026

