Controls for delegated operations.
Defined access, approval authority, dual control, credential management and documented escalation across the functions Opsist operates.
Control framework
Control framework.
Access management
Access is requested, approved and recorded per system. Team members receive the minimum access their function requires, and access is reviewed when scope or staffing changes.
Payment and approval workflows
Payments follow a defined approval path with documented thresholds. The person who prepares a payment is not the person who releases it.
Dual-control principles
Sensitive actions, new payees, bank detail changes, payroll changes, require a second person to verify before execution.
Credential handling
Credentials are stored in managed secret storage rather than shared documents or messages. Shared logins are replaced with individual accounts wherever the system supports it.
Data minimization
We request the data required to run the functions in scope, and no more. Where a task can be performed without personal or financial detail, it is.
Vendor access
Third-party access is inventoried, scoped and reviewed. Vendors that no longer require access are removed as part of the vendor register review.
Role-based permissions
Permissions are assigned by role rather than individually, so joiners and leavers are handled consistently.
Incident escalation
Suspected incidents follow a defined escalation path with founder notification, containment steps and a written record of actions taken.
Business continuity
Functions are documented in runbooks so coverage does not depend on a single individual being available.
Audit trail and documentation
Approvals, exceptions and changes to process are recorded so that a third party can reconstruct what happened and why.
Security practices vary by system and engagement; specific controls are documented during onboarding. This page describes general practice and is not a contractual commitment. Certification or coverage requirements for a specific engagement are addressed during the Ops Audit.
Onboarding
Onboarding controls.
- The systems Opsist has access to, at what permission level, and who holds it
- The approval thresholds and the people who hold approval authority
- Which actions require dual control
- How credentials are stored and rotated
- The escalation path and notification expectations for incidents
- How access is removed at the end of an engagement
Each control has a named Opsist owner. Accountability for the functions Opsist operates sits with the leadership team.
Start Your Free Ops Audit
A structured review of finance, cash, people, customer and systems operations, with a written view of what Opsist would own, what would change first, and whether a partnership fits.
