Access controls protect records from unauthorised use while supporting legitimate business needs.
Over-permissive access increases risk, while overly restrictive access hinders productivity.
Balance is essential.
Questions:
- Are access rights reviewed regularly?
- Are they role-based?
Action: Check access permissions for one shared repository.