ssm.ro Docs
Security, Infrastructure & OperationsAccess Control & Identity

Periodic Access Review

Client responsibility — Super User manages users; the platform provides the necessary tools

Responsibility Model

In SSM.ro's Shared (multi-tenant) model, user accounts and role assignments are managed entirely by each client's own Super User, within their commercial account.

SSM.ro as the platform vendor does not assign, modify, or review clients' internal access rights — this responsibility, including periodic review, belongs to the client's Super User.

Tools Provided by the Platform

To support periodic access review, the platform provides the Super User with:

  • User list for each organization, with assigned roles (User / Control-Audit / Employee Personnel)
  • Self-service addition and removal of users at any time
  • Client activity logs retained in Postgres for 3 months, accessible and downloadable by the Super User for record-keeping and review purposes

Client Responsibility

The documented periodic review process — review cadence, reviewer identity, evidence retention (e.g., dated review emails or approval records) — is owned and operated by the client's Super User.

Evidence for this audit point must be extracted from the client's own records, not from the vendor. SSM.ro does not perform reviews of clients' commercial accounts on their behalf.

Roles Available for Review

RoleLevelPermissions
Super UserCommercial accountAll operations; user and organization management
UserPer organizationManagement access, adding/removing employees and documents
Control / AuditPer organizationRead-only view of employees, org chart, approved documents
Employee PersonnelPer organizationAccess to their own documents and documents addressed to them

Note: A user can hold different roles in different organizations within the same commercial account.

Activity Logs

Activity logs available for review include:

  • Document deletion events
  • Report downloads (on request, as an additional feature)
  • Other relevant operational events

More advanced and granular activity logs may be implemented in the Enterprise package.