Finance
Purchasing Approval Matrix
20 approved policy statements are activated from this source.
DOC-FIN-0003 · SRC-5636F94E1DA4FF8CE9D9C95FD0CDPROOF SPACE
See how SALARA turns a policy document into activated Organizational Intelligence, then ask a question and Replay the evidence behind the answer.
Policy document experiences
Each available document is backed by activated Organizational Intelligence.
Finance
20 approved policy statements are activated from this source.
DOC-FIN-0003 · SRC-5636F94E1DA4FF8CE9D9C95FD0CDHuman Resources
54 approved policy statements are activated from this source.
DOC-HR-0005 · SRC-1DE734B79FD1BA337ED2D3E066EEInformation Security
19 approved policy statements are activated from this source.
DOC-IT-0003 · SRC-594156BCE10E5BB8CEFC271A91E2Information Security
20 approved policy statements are activated from this source.
DOC-SEC-0004 · SRC-565D08896030A88C111A7224DF98Information Security
31 approved policy statements are activated from this source.
DOC-SEC-0005 · SRC-6E538DE827A73F0439799AD79070IT Operations
58 approved policy statements are activated from this source.
DOC-OPS-0003 · SRC-5991452A065397B573265DC07B98Document content
These approved statements are the content Runtime can use. Answers stay inside this activated boundary.
Information Security · Activated document
- Unused privileged access is revoked after thirty days of inactivity.
ASSERT-122B56CA8FA341FFDF032AE05FB48B20 · v1- Access that can read an entire customer dataset is treated as privileged.
ASSERT-1C4CD5CDC1FC766AD9E355DD278F9B32 · v1- Every privileged session is recorded in the privileged access management platform.
ASSERT-38061A69730F144E14FF3FD53B042032 · v1- Administrative access to customer production systems is always privileged.
ASSERT-441D8719D7EFD1E1A0FF431910B09843 · v1- Elevation beyond eight hours requires CISO approval.
ASSERT-516E5CD53C5024CE11617FDFCD230F7D · v1- Shared administrator credentials are prohibited across all Compass One systems.
ASSERT-5992ED41A6603467612B34CBF75C5C0E · v1- Privileged access is any credential that can alter security controls.
ASSERT-5B4F9CF263A6FEE94FDC60505F65E870 · v1- Security must review privileged access grants each quarter.
ASSERT-64F0B337033D4CB4501D4BAFEA14693E · v1- Privileged access is revoked within one hour of an employment termination notice.
ASSERT-670E9FAB70634CA4ED51C3BD3AD72CBD · v1- The requester must state a specific business justification for every elevation.
ASSERT-86FE885D750586A85987069ABB2127D5 · v1Privilege is determined by what a credential can do, not by the job title of the person holding it.
ASSERT-8C140CD7218DD4BC2EAB62A0D5866543 · v1- All privileged sessions must originate from a managed Compass One endpoint.
ASSERT-91C1F53546643D85D5171D0B3961DB77 · v1- A privileged access request requires manager approval with Security review.
ASSERT-98BC473F741DE4F641A3C1CC9306FA1E · v1- Break-glass credentials are sealed in the emergency vault.
ASSERT-99A2A95EA84D4DF0FC767407C3BC223F · v1- Session recordings are retained for eighteen months.
ASSERT-9A9D0A3450C6EF906D4B6435BE926CCA · v1- Security must rotate a break-glass credential immediately after use.
ASSERT-A786ED256C3536C32DC7E959E39D1EC9 · v1- Any break-glass use must be reported to the CISO within one hour.
ASSERT-A9F2760175AA70D8518B7A85ABF6AC0B · v1- The CISO owns this standard.
ASSERT-D35A7A9D18D24542D2D984AC76BF12F5 · v1- Privileged sessions are limited to four hours by default.
ASSERT-D3C2A3D05C430A9FCD0D99385061B597 · v1- Privileged access from personal devices is prohibited.
ASSERT-DAC746FB2844FBFCC876CD331B2981D8 · v1From the activated intelligence
These examples are derived deterministically from approved Assertions in the active compiled artifact.
What does the policy say about - Unused privileged access is revoked after thirty days of inactivity?
Ask this questionWhat does the policy say about - Access that can read an entire customer dataset is treated as privileged?
Ask this questionWhat does the policy say about - Every privileged session is recorded in the privileged access management platform?
Ask this questionWhat does the policy say about - Administrative access to customer production systems is always privileged?
Ask this questionWhat does the policy say about - Elevation beyond eight hours requires CISO approval?
Ask this questionWhat does the policy say about - Shared administrator credentials are prohibited across all Compass One systems?
Ask this questionOne discipline, four ways to explore