×

Engineering Portal Access Control>

Granular Access Control for Multi-Application Portals

01/06 Project Context

The existing system relied on only four static roles (visitor, authenticated user, administrator, super administrator). This structure was too limited for the engineering portal, which hosted a wide range of services and applications, each with unique access requirements.

A new approach was needed: one where users could have different roles across different applications, some temporary, some permanent, while ensuring that no user could access the backend.

This decision was critical both for security and for compliance with ISMS standards, especially as the company was preparing for TISAX certification.

Summary

  • Problem: Only 4 global roles, insufficient for multiple applications.
  • Requirement: Application-specific and feature-specific access levels.
  • Restriction: No backend access for any user.
  • Flexibility: Ability to assign multiple roles per user per application.
  • Granularity: Support for read-only, logging, moderation, approval, and override roles.
  • Compliance: Alignment with ISMS principles and TISAX certification needs.

02/06 Challenges

Designing an access control model for a multi-application portal required balancing flexibility with security. The system had to allow dynamic role assignments without granting unnecessary privileges, while preventing any path into the backend environment.

Limited Roles

Only 4 global roles existed, not enough for diverse applications.

No Backend Access

Security required preventing backend access entirely.

Complex Needs

Applications demanded unique access models such as viewers, approvers, and overrides.

Scalability

The system needed to support multiple roles across multiple applications.

03/06 Solution

The solution was to extend the registered users module and create an application-aware access model. Each user starts with no roles, and permissions are assigned through a repeatable region tied to applications and services. Roles are chosen from each application’s global settings, with the option for time-limited access. This structure ensured that access remained flexible, auditable, and secure, while aligning with compliance requirements.

Application-Specific Roles

Users can have different roles per application, independent of global roles.

Time-Limited Access

Temporary roles granted until a specified date and time.

Request Workflow

Users can request access with justifications for audit purposes.

04/06 Technical Aspects

The system was designed around modularity and auditability. Role assignments are stored in the extended user module, isolated from the backend. The design allowed multiple roles per user and even multiple roles within a single application, ensuring that engineers had the right access at the right time without requiring backend exposure.

Dynamic Role Mapping

Roles tied to specific applications with granular permissions.

Multi-Role Support

Users can hold multiple roles across applications or within one application.

Access Requests

Workflow to justify and approve new role assignments.

05/06 Compliance Alignment

The access control system was designed with ISMS requirements and TISAX certification in mind. It followed principles of least privilege, segregation of duties, and auditability to ensure both security and compliance. These compliance-aligned design choices provided confidence that sensitive engineering data was properly safeguarded, while supporting the organization’s certification goals.

Least Privilege

Users granted only the access strictly needed per application.

Audit Trails

Access changes and requests logged for full traceability.

Temporary Roles

Time-limited access ensured compliance with sensitive project needs.

06/06 Outcome & Reflection

  • Improved Security: Backend exposure eliminated.
  • Flexibility: Roles aligned to each application’s unique needs.
  • Scalability: Model supports new services without redesign.
  • Compliance: Strengthened ISMS posture, supporting TISAX readiness.

Lessons Learned

  • Granularity adds complexity but ensures long-term flexibility.
  • Request workflows improve auditability but must remain user-friendly.
  • Compliance alignment should be built from the start, not added later.

WRITE

General
contact@a-ag.nl
Support
support@a-ag.nl

CALL

WhatsApp
+31 (0) 645 632 583
Call
+31 (0) 645 632 583

A-AG

KVK
99673592
BTW-ID
NL005402899B82