Users only have access to what their role requires
Sekit's Least privilege / RBAC control defines the access each role needs and makes that the default grant, the policy half of A.5.15's set-and-enforce requirement; the platform-level enforcement that completes it is mapped separately on this page.
Defining the access each role needs and granting from that definition rather than copying a colleague supports A.5.18's provisioning step, though the review and revocation legs the control also requires sit with other Sekit controls.
This Sekit policy commits each role's access needs to a written definition and makes it the default grant, laying the groundwork for the access restriction A.8.3 requires without itself restricting anything until enforced elsewhere.
https://sekit.ai/api/mcp/crosswalk