MCMMCM DocsEngineering (Internal)
User StoriesMCM-57 — Legal & Compliance Readiness for Customer Deployment
v1.2 is unreleased — see v1.1 for the current stable release.

MCM-59 — Cross-Account Access & Least-Privilege Commitments

Documented, contractually-committed least-privilege scopes for every cross-account role MCM requests.

MCM-59 — Cross-Account Access & Least-Privilege Commitments

← Back to Legal & Compliance Readiness overview

As Compliance & Security Lead,
I want documented, contractually-committed least-privilege access scopes for every cross-account role MCM requests,
so that customers can evaluate and approve MCM's access before granting it, and any breach involving MCM's access has clear contractual accountability.

Acceptance Criteria

  • Every cross-account role or permission set requested by discovery, governance, secops, orchestration, and finops is documented with its exact scope and the business justification for each permission.
  • The contract includes a least-privilege commitment: MCM will not request permissions beyond what's documented, and any expansion requires customer notice and re-approval.
  • A customer-facing permissions reference is published so a customer's security team can review the exact access being granted before onboarding.
  • The contract defines liability allocation for a security incident that originates from MCM's granted access, as distinct from the customer's own environment.
  • Access-scope changes between releases are reviewed by the Compliance & Security Lead before rollout, not discovered after the fact.

Technical Design

Each module's cross-account role request is compared against the published permissions reference before a release ships; any new or changed permission triggers a documented justification and an update to that reference, which is also the document the contract's least-privilege clause points to — so the legal commitment and the actual requested access can never drift apart unnoticed.

On this page