---
title: What are Access Control Best Practices? - TrueVault
description: What are Access Control Best Practices? - TrueVault
---

<https://safe.truevault.com/?hsLang=en>

- [CCPA](https://safe.truevault.com/learn/ccpa/what-is-the-ccpa)
- [GDPR Compliance](https://safe.truevault.com/gdpr-guide)
- [Personal Data](https://safe.truevault.com/learn/what-is-personal-data)
- [DSAR](https://safe.truevault.com/learn/explaining-gdpr-data-subject-requests)
- [HIPAA](https://safe.truevault.com/learn/hipaa)
- [HIPAA Compliance](https://safe.truevault.com/blog/hipaa-compliance-checklist-download.html)
- [Personally Identifiable Information](https://safe.truevault.com/blog/what-is-phi)
- [PHI](https://safe.truevault.com/protected-health-information)

- [Resources](https://safe.truevault.com/learn/) 
    - [Resource Center](https://safe.truevault.com/learn/)
    - [TrueVault Safe](https://safe.truevault.com/help/truevault-safe)
- [About](https://safe.truevault.com/about-us)
- [Contact](https://safe.truevault.com/contact-us)
- [Careers](https://careers.truevault.com/)

- Solutions 
    - [GDPR Compliance](https://safe.truevault.com/solutions/gdpr-compliance)
    - [HIPAA Compliance](https://safe.truevault.com/hipaa-compliance)
    - [For Applications](https://safe.truevault.com/solutions/application-compliance)
    - [For Data Exchanges](https://safe.truevault.com/solutions/data-exchange-compliance)
- [Developers](https://safe.truevault.com/resources/index)
- [Pricing](https://safe.truevault.com/safe-pricing)
- [Blog](https://safe.truevault.com/blog)
- [Login](https://console.truevault.com/login)
- [Get Started](https://safe.truevault.com/get-started)

Resources

- [Home](https://safe.truevault.com/homepage-v3?hsLang=en)
- [Resources](https://safe.truevault.com/resources/index?hsLang=en)
- What are Access Control Best Practices

# What are Access Control Best Practices?

Proper Access Control is an important part of securing your data. If your rules are too permissive, the wrong users may get access to sensitive information. The guidelines here will help steer you in the right direction. If you have further questions, don’t hesitate to [ask](mailto:help@truevault.com).

See also: [access control basics](https://safe.truevault.com/resources/developer/how-do-i-implement-access-control?hsLang=en).

### 1. A User for Everyone!

First and foremost: make sure there is a distinct user for every person who uses your product. Each user should have their own username & password (ideally they should use [MFA](https://safe.truevault.com/resources/developer/how-do-i-enable-mfa-for-truevault-users?hsLang=en) as well).

It is bad practice to share logins, or have an “office” login that represents a group of people. Doing so makes it impossible to lock down specific access based on unique user attributes. Even if all users in that office should have the same access, this makes it impossible to correctly correspond Audit Log entries with the person who took the action. That audit log gap violates HIPAA. If that’s not enough to convince you, it’s just plain bad hygiene. It’s likely these users would share credentials using email or sticky notes, which greatly increase the chance of outside compromise.

Moral of the story: make sure each human being has their own user.

### 2. Less is More

The principal of least privilege is the cornerstone of a good security policy. Simply put, this principal says that if someone doesn’t *need* access to something, don’t give it to them. For example, if you’re building a health care application for doctors in a hospital, you could give all doctors access to all patients. But is that necessary? Would it be sufficient to give doctors access to all patients that the doctors *actually work with*? This may not seem like a big deal on the surface: you trust these doctors so why restrict their access? But this means that a compromise of a single doctor compromises the entire patient set. A doctor is as likely as anyone else to have malware on their computer or to fall for a phishing scam.. You should minimize any user’s access, regardless of how much you trust the user, to mitigate the loss if their account is compromised.

### 3. Keep it Current

You should regularly audit your access control rules to ensure they are current. You can do this from the TrueVault [Management Console](https://console.truevault.com) on the Groups tab. Each group shows what resources are accessible and which actions are allowed. This declarative nature makes it straightforward to understand the net-effect of a group policy. Each group also lists every user who is a member on the right, so you can ensure membership is current as well.

### 4. Keep it Simple

The best way to stay true to #3 is to make it easy to audit your access control rules regularly. That’s why we try to make common patterns like [Ownership](https://safe.truevault.com/resources/developer/how-do-i-make-sure-users-have-access-to-only-their-own-documents-and-blobs?hsLang=en) as concise to express as possible. When you’re writing your own policies, do your best to keep them simple and organized so they can be easily audited. Don’t let this trump the other rules though; simplicity is not as important as enforcing minimal access.

### 5. Get some help!

We have a team of experts on staff who can help you decide how to model your access control. Once you sign up, don’t hesitate to ask for help along the way, or get a second pair of eyes before you go live.

### Latest Posts

## [Should Utah's Privacy Law Be on Your Radar?](https://safe.truevault.com/blog/utah-privacy-law-does-it-apply?hsLang=en)

 Phillip Walters  / November 17, 2022

## [Connecticut’s Privacy Law: Does It Apply to Your Business?](https://safe.truevault.com/blog/connecticut-privacy-law-does-it-apply?hsLang=en)

 Phillip Walters  / November 10, 2022

## [Global Privacy Control: A New Requirement for Compliance](https://safe.truevault.com/blog/global-privacy-control?hsLang=en)

 Phillip Walters  / November 7, 2022

### Mailing List

### Company

- [Blog](https://safe.truevault.com/blog)
- [Contact Us](https://safe.truevault.com/contact-us-2019)
- [Careers](https://truevault.workable.com)
- [HIPAA Compliance Checklist](https://safe.truevault.com/blog/hipaa-compliance-checklist-download.html)
- [PDF: Developers Guide to HIPAA compliance](https://my.leadpages.net/leadbox/14472b173f72a2%3A131fd12f8b46dc/5760820306771968/)

### Developers

- [Patterns](https://safe.truevault.com/patterns)
- [Documentation](https://docs.truevault.com/)
- [Quick Start Guide](https://safe.truevault.com/quick-start-guide)
- [Secure Infrastructure](https://safe.truevault.com/secure-infrastructure)
- [API Overview](https://safe.truevault.com/api-overview)

### Latest Posts

### Contact Us

201 Mission Street, 12th Floor  
 San Francisco, CA 94105  
 Email: [hello@truevault.com](mailto:hello@truevault.com)

2021 © All Rights Reserved. [Privacy Policy](https://privacy.truevault.com/privacy-policy) | [Terms of Service](https://safe.truevault.com/terms-of-service?hsLang=en)

- <https://www.facebook.com/truevault?fref=ts>
- <https://www.linkedin.com/company/truevault>
- <https://twitter.com/truevault>