Security and Governance in PracticeLast updated: 6 August 2026
Applying Least Privilege
In the security domain, least privilege means giving each person only the access they need for their work, and no more. This reduces risk if an account is misused or compromised.
In SFS Access, access is controlled by what actions a role can perform. Three built-in roles cover most common needs:
- Viewer — can list and download files only.
- Contributor — can list, download, and upload files, with selected companion-sensitive operations in supported environments.
- Enclave Admin — full operational access including delete, membership management, policy control, and lockdown.
What to review during security checks
- File operations: list, upload, download, delete.
- Governance operations: membership management, policy management, lockdown.
- Companion-sensitive operations: token and external-share actions when companion add-ons such as SFS Vault or SFS Gateway are being used.
Practical guidance:
- Assign most users the Viewer or Contributor role unless there is a specific reason for elevated access.
- Keep the number of Enclave Admin members small and review it regularly.
- If a user temporarily needs elevated access, assign it, complete the task, then return the role to its baseline.
In plain terms: keep powerful roles rare, give temporary elevation only when needed, and review regularly so access does not quietly expand over time.
Security Incident Containment
Use this process when you suspect a security breach or policy misuse in an enclave. The goal is to reduce exposure quickly, check what happened, and then restore access safely.
Step 1 — Restrict the affected enclave straight away
Lock the enclave first. In the Control Panel, open Secure Areas (Enclaves), select the affected enclave, run the Lock action, and confirm. This blocks enclave operations while you assess the issue.
Step 2 — Review the Security Activity Log
Check recent activity for unusual patterns, unexpected operations, or repeated denials that may indicate misuse.
Step 3 — Suspend specific memberships if needed
If a particular account is in scope, deactivate its enclave membership while the investigation continues.
Step 4 — Confirm outcomes with Effective Access Check
Run Effective Access Check for the accounts you are reviewing to confirm access now matches your containment intent.
Step 5 — Restore access in controlled stages
When conditions are stable, unlock the enclave and restore memberships in small steps. Confirm each step in the Activity Log and with Effective Access Check before moving on.
OTP in this flow
OTP is a security enhancement for high-risk changes. Where enabled and required, complete OTP verification before lock, unlock, or other privileged changes are applied.
Governance and Audit Readiness
Many organisations need to show that sensitive file access is controlled properly, whether for internal review, client assurance, or formal audit.
SFS Access helps by making access decisions and access evidence easier to explain:
- Policy-based decisions — each allow or deny outcome comes from defined rules, not informal exceptions.
- Security Activity Log — records key security and governance actions across enclaves.
- Eligibility pools — keep access scope grouped and reviewable at team level, not only per individual.
- Effective Access Check — lets you show current access for a member and enclave at the point of review.
The practical benefit is readiness. When a governance question is raised, you can answer with current, traceable information rather than trying to reconstruct past decisions from memory.
OTP and High-Risk Operations
SFS Access works well without OTP Pro being installed. Adding OTP Pro adds an additional security layer to selected high-risk changes in SFS Access configuration.
Baseline versus OTP Pro enhanced operation
- Baseline mode: core enclave, pool, membership scope, and policy governance workflows are available.
- OTP Pro enhanced mode: selected privileged changes require a fresh OTP verification (i.e. one performed within the last 5 minutes).
Examples of changes that may require OTP
- assigning or deactivating memberships
- saving role permission changes
- locking or unlocking an enclave
- editing enclave identity details or upload-location bindings
- secure location creation where directory changes are required
How fresh OTP works
When OTP Pro is installed, and the current user is performing a privileged action, SFS checks before authorising the action that a recent OTP verification has been completed by the user; if it cannot find a recent verification SFS starts a new OTP verification, when that is completed successfully SFS resumes the pending action.
Companion-sensitive capability behaviour
- When OTP Pro is unavailable and / or not configured for the current user, some actions are hidden or blocked - for example, SFS Vault is not accessible to users who have not completed OTP verification.
- Control Panel notices explain which companion capabilities are currently unavailable.