User Management, Profiles and Access Control Policy
Rules for creating users, invitations, groups, profiles, permissions, links to properties and traceability.
- Version
- 1.0
- Published on
- July 1, 2026
- Last updated
- July 1, 2026
- Next scheduled review
- July 1, 2027
1. Purpose
This Policy establishes rules for the creation of users, invitations, groups, profiles, permissions, links to properties and traceability.
2. Principles
HABORA will adopt least privilege, deny by default, segregation by company, individual identification, traceability, periodic review and deactivation of unnecessary access.
3. Identity
Email will be used for invitation, login and communication. Actual authorization must be based on user_id, company_id, group_id, property_id, module and permitted action.
4. Profiles
Suggested profiles include Owner, Admin, Manager, Legal, Finance, ESG, Operational, Auditor, Read Only, External User and Platform Admin.
5. Groups
Groups allow permissions to be assigned by function or area, such as Administration, Legal, Finance, ESG, Operational, Consultants, Audit, Franchisees and Read Only.
6. Permissions
Permissions may include view, create, edit, delete/deactivate, export, generate reports, invite users, manage permissions, approve critical actions and receive alerts.
7. Link to properties
The user must only access properties and data to which they are linked. This rule applies to the dashboard, contracts, documents, reports, AI, finance, ESG, alerts and global search.
8. Invitations
Invitations must record email, name, company, groups, properties, permissions, responsible party, status, creation, expiration, acceptance or revocation.
9. Deactivation
Removed users must not be physically deleted when there is relevant history. They must be deactivated, preserving logs and traceability.
10. Review
Admins must periodically review active users, external users, critical permissions, financial access, deletions and groups.
Contact
Questions, legal requests, privacy requests, formal communications and requests related to this policy should be sent to juridico@haborahub.com.br.
Updates
This policy may be revised to reflect legal, regulatory, technical, commercial or operational changes. The current version will remain available in the HABORA Compliance area. Material changes may require new acceptance by users, where applicable.