← Back to the blog
Sunset Docs blog

Who should see client documents? A least-privilege checklist

A practical access review for deciding who may view, download and delete temporary client documents.

Give access to a client document only when a named person needs it for a defined task. Viewing, downloading originals, changing deletion dates and deleting submissions are different permissions. They should not automatically travel together.

That is the practical meaning of least privilege for document intake. A colleague may need to confirm that a form is complete without needing the original on their laptop. A team lead may need to extend a deletion date without reading every submission. An IT administrator may maintain the service without having a business reason to inspect client files.

The rule is simple to state and easy to lose in day-to-day work: access follows the task, not seniority, curiosity or convenience.

Start with the document, not the job title

Broad roles such as "operations", "finance" or "partner" do not explain why someone needs a particular document. Write down the action that completes the work.

For example:

  • Confirm that a requested statement covers the correct period
  • Check that a signed form contains all required fields
  • Approve an exception to the normal deletion date
  • Retrieve an original because another approved system requires it
  • Remove a submission after the process is complete

Then assign the narrowest access that permits that action. The NIST definition of least privilege calls for the minimum access needed to accomplish assigned tasks. The European Data Protection Board's small-business security guidance recommends differentiated authorisation profiles, unique user accounts and regular permission reviews.

These sources do not prescribe one role model for every business. Your access design should reflect the documents, people and risks in your own process.

Use four separate permission questions

For each person or role, ask four questions.

1. Do they need to view the submission?

Viewing is enough for many checks. If a reviewer only needs to read a page and record an outcome elsewhere, do not make downloading the default.

View-only access still exposes the information on screen. It cannot stop a screenshot, photograph or transcription. Treat it as a way to reduce routine copies, not as copy prevention.

2. Do they need the original file?

Original downloads create a new copy outside the intake service. That copy may inherit a different retention period, backup schedule and access group.

Require a concrete reason. "We sometimes need it" is not enough. A better rule is: "The case owner may download the original only when the approved system requires the source file, and must then place it in that system." Record the exception if the service supports an audit trail.

3. Do they need to change or end retention?

Changing a deletion date can keep information available for longer than the sender was told. Deleting early can interrupt work or remove a record that should first be transferred to an official system.

Limit both actions to people who understand the process and its retention rule. A temporary intake service is not the place to decide statutory retention from memory. The business should define that rule separately and document any legal hold or exception.

4. Do they need to manage other users?

Inviting members and changing permissions are administrative powers. A frequent reviewer does not automatically need them. Keep at least one accountable owner, avoid shared administrator accounts and remove access promptly when a person changes role or leaves.

A working access matrix

Use this table as a starting point. Replace the example roles with named functions in your business.

Role Business task View Download original Change deletion date Delete Manage members
Intake coordinator Confirm receipt and completeness Yes No No No No
Assigned reviewer Assess the submitted information Yes By exception No No No
Process owner Resolve exceptions and close the work Yes By exception Yes Yes No
Workspace owner Manage service settings and access Only if the task requires it By exception Yes Yes Yes
External adviser Review one defined submission Time-limited if supported No by default No No No
IT support Maintain accounts and devices No document access by default No No No Account administration only if required

For each "Yes", add an owner and a review date. For each "By exception", define who approves it and where the reason is recorded. If your service cannot express the distinction, reduce workspace membership and handle the remaining control through a written procedure.

Sunset Docs separates workspace ownership from membership, reserves retention and original-download permission changes for the owner, and records material document activity. Its viewer can avoid sending the original to the browser during ordinary review. These controls help with a least-privilege process, but they do not decide who your business should invite or stop an authorised viewer from reproducing what they can see. The Security page describes the current boundaries.

Review access when the work changes

A quarterly review is a sensible operational default for many small teams, but it is not a legal period. Review sooner after a departure, role change, contractor handover, suspected account compromise or change in the documents you collect.

Run the review against named accounts, not a remembered team list:

  1. Export or open the current member list.
  2. Confirm that every account belongs to a current person.
  3. Ask the process owner to confirm each person's current task.
  4. Remove access that is no longer needed.
  5. Check who can download originals or manage deletion.
  6. Confirm that owners use their own accounts and have two-step verification enabled where available.
  7. Review recent access, download and deletion events for activity that does not fit the assigned tasks.
  8. Record the reviewer, date, changes made and next review date.

Do not keep a detailed review spreadsheet inside the document inbox. It belongs with your security or governance records and should identify accounts and decisions without reproducing client document contents.

Keep notifications and support access narrow too

Access control extends beyond the document viewer. Submission notification emails should not contain filenames, document previews or sensitive circumstances. They only need to tell the recipient that a submission is ready.

Support access deserves the same scrutiny. Ask a provider whether its staff can read customer documents, what approval is required, whether access is time limited and whether the action is logged. The NCSC cloud security principles recommend controls that constrain and audit provider personnel with access to customer data.

Do not solve a data-fit problem with permissions

A perfect access matrix does not make every document suitable for a service. Before collecting anything, check the provider's terms, your lawful basis, required notices and any sector rules.

Sunset Docs is not authorised by default for children's data, criminal-conviction data, biometric data used for unique identification, full payment-card data, credentials or special-category data such as health information. A separately agreed arrangement may be required for some categories, and some processes need a different system entirely. Restricting the member list does not change that boundary.

The service is also not an identity-verification tool or permanent archive. Move any record that must be kept into its approved system before the temporary intake copy is deleted. For the wider intake flow, see how to collect sensitive documents without email attachments.

Frequently asked questions

Should every manager be a workspace owner?

No. Ownership should follow administrative responsibility for the workspace, not a person's place in the reporting line. A manager who only reviews submissions may need ordinary review access and nothing more.

Is view-only access enough for confidential documents?

It can reduce routine downloads, but the viewer still sees the information and can reproduce it. Combine view-only review with named accounts, appropriate authentication, a clear task, short retention and an audit trail.

Can we use one shared account for a team?

Avoid it. Shared accounts weaken accountability and make departures or permission changes harder to manage. Give each person a separate account and remove it when access is no longer needed.

How often should access be reviewed?

Choose a frequency that matches staff turnover, document sensitivity and the pace of role changes. A small stable team might use a quarterly review plus event-driven checks. A fast-changing or higher-risk process may need more frequent review.

Should external advisers get access?

Only if their task requires direct access and your agreements, notices and service controls support it. Prefer time-limited access to a defined matter. Remove it when the review ends and do not give administrative permissions by default.

Does least privilege make the workflow compliant?

No. It is one security practice. The organisation collecting the documents remains responsible for its lawful basis, transparency, data minimisation, retention, processor assessment and any sector-specific duties.