TRUST CENTRE · ASSURANCE STANDARD

Privileged Support Access & Break-Glass Standard

PUBLIC ASSURANCELast updated: September 2026PCL OneVersion 1.0
Scope: PCL One personnel and approved service providers requiring administrative access
Baseline Commitment

PCL One does not rely on unrestricted standing access to customer data. Administrative support access uses named accounts, MFA, least privilege, approval, logging and time-bound elevation. Emergency break-glass access is disabled by default, dual-authorized when activated, time-boxed and reviewed after use.

Normal support access model

Normal support access model table
StepControl
1. Need establishedA support case, approved maintenance task, security event or other documented service need establishes the purpose for access.
2. AuthorizationThe requested access is approved under the engagement’s support/security model; customer approval is used where the service schedule requires case-by-case authorization.
3. Least privilegeOnly the role, environment and data scope necessary for the task are granted. Named administrator accounts are used.
4. Strong authenticationMFA is required for administrative access. Federated access may use the customer or PCL One identity provider according to the agreed design.
5. Time-bound elevationPrivileged access is activated only for the required window and removed or expires when the task is complete.
6. Logging & reviewAdministrative activity is logged. Material or emergency access is reviewable and may be included in customer assurance evidence.

Break-glass access

  • Break-glass or emergency access accounts are disabled by default wherever the architecture supports that model.
  • Activation is reserved for events such as federated sign-on failure, a critical service recovery event or another condition where normal administrative access cannot safely restore service.
  • Activation requires dual authorization, is time-boxed, and every use is logged and reviewed after the event.
  • Break-glass access does not remove the requirement for least privilege, evidence preservation or customer incident communication.

Customer data and geography

  • Support personnel access customer data only when necessary to provide the contracted service, troubleshoot an issue, perform approved maintenance or respond to a security event.
  • Remote support access does not by itself relocate the stored customer dataset. For a Canada-only municipal deployment, customer data, backups and recovery copies remain in the approved Canadian regions.
  • Processing outside the approved residency model requires disclosure and the customer approval/contract treatment specified for the engagement.
  • Approved subprocessors with support access are subject to equivalent minimum-necessary, confidentiality and security controls appropriate to their role.

Customer control options

  • Named customer approvers for privileged support access.
  • Case-by-case approval for data-level access where operationally feasible.
  • IP/network restrictions, support windows or additional access conditions where supported by the service architecture.
  • Periodic administrative-access review and assurance reporting where agreed for the service.

Assurance records

  • Named privileged account inventory
  • MFA / identity configuration evidence
  • Privileged access grant and expiry records
  • Administrative/audit log extracts
  • Break-glass activation and post-use review record
  • Periodic access certification results

Applicability

This document states PCL One’s public assurance baseline. A customer agreement, service schedule, applicable law or regulator requirement may set additional or stricter obligations; those terms take precedence for the applicable service. Service-specific architecture, residency and retention settings are documented in the relevant service schedule.

Explore more assurance standards

Related customer-facing commitments

INCIDENT RESPONSE

Security Incident & Breach Notification

How material security incidents are assessed, communicated and followed through to resolution.

SUPPLY-CHAIN TRANSPARENCY

Subprocessors & Third-Party Services

How service providers are governed and how relevant third-party involvement is disclosed.

PHOTO AND ATTACHMENT METADATA

Location Metadata & Uploaded Media

How potentially sensitive location metadata associated with uploaded files and media is handled.

Canadian Municipal Expertise|
ERP Implementation Capability|
PSAB-Aware Delivery|
Canadian Data Residency
Utility Billing · Property Tax · Permitting · Licensing · Asset Management · Work Orders