Access scoped per account, evidence produced per account, and provisioning that keeps up with the turnover.
Your clients hand you information they are answerable for: customer records, patient billing, financial statements, engineering drawings, transaction data. They stay accountable for it to their own regulators and customers, which is why what you do with it is written into your contract and checked. On your side that data passes through many hands and many roles, and the people holding it change faster than in most businesses. Those two facts together decide what protecting it takes.

Access by role means an agent, an analyst and a team lead hold different entitlements over the same client's data, and each holds the minimum their work requires. Entitlements sit on the role rather than on the person, so the question of who can see a client's records has one answer instead of one per employee. Where a role needs more, the request routes to whoever owns that resource and the reason is recorded with the approval.

What breaks segregation is movement: someone picks up a new client's role and keeps the previous one's entitlements. Akku's segregation of duties engine holds the combinations you have declared incompatible and blocks them at the point a move would create one, including where the conflict comes through a nested role. Each client's records are indexed separately as fingerprints, so a file belonging to one engagement is caught if it turns up on another.

Provisioning from role means a starter receives exactly what that role carries, without anyone assembling it from memory or copying it from a colleague. The same mechanism runs in reverse at exit: deprovisioning in one action across every connected system. At the volumes this work hires and loses people, the difference between a defined role and a manual checklist is the difference between a clean handover and a finding.

Screenshot, clipboard, print and removable media are controlled at the endpoint, which is where a contractual obligation actually lands. Delivery work runs to a roster from known locations, so access can be restricted to the hours a role works and to your own IP ranges. Shared workstations need the access decision at sign-in rather than at setup.

Where your people administer systems belonging to a client, every session runs through a proxy that generates the credential for that session and revokes it at close. The engineer connects and works; the password never reaches their machine. The screen is recorded and every command logged, which is the artefact a client asks for after an incident on their side.

Every report runs for a defined window and a defined scope: who held access to that client's systems, who approved it, what happened in a privileged session, what data moved and where. Because records are written as the access happens, a request covering a quarter that closed months ago is a query rather than a reconstruction.

ISO 27001 and increasingly SOC 2 Type II arrive in the security questionnaire rather than in a compliance review. Akku covers 56 of the 93 ISO 27001 Annex A controls and 34 of the 61 SOC 2 Trust Services Criteria, and holds both certifications itself. The DPDP Act applies to personal data you process for a client as much as to your own employee records.
