ACCESS LIFECYCLE
Four stages, and the paper each one leaves behind.
| Stage | 01Vet | 02Authorize | 03Log | 04Revoke |
|---|---|---|---|---|
| Artifact | Status check | Signed addendum | Session log | Disabled account |
| Who owns it | Security | Program manager | IT | Security |
| Cadence | On assignment | Per program | Continuous | On departure or quarterly |
Access is a named list, not a department. Every stage above produces an artifact somebody can audit.
WHO TOUCHES THE WORK
Access is a named list, not a department.
On export-controlled programs, the question is never “which team” but “which people.” Here is how we answer it, person by person, program by program.
U.S. PERSONS
U.S. persons only, by definition.
Everyone with access to the compliant environment meets the U.S. person definition in ITAR §120.15. This is a staffing rule, not a paperwork exercise, and it applies before any program access is granted.
PER-PROGRAM LIST
A roster on file for every program.
Each export-controlled program carries its own authorized personnel roster. If a name is not on the list for that program, that person does not open its files. Each authorized person also signs a data-handling addendum on top of the standard NDA.
REVOCATION
Offboarding is a procedure, not a habit.
When someone rolls off a program or leaves the company, a documented revocation procedure removes their access. Accounts are disabled, the roster is updated, and the change is logged.
HOW WE RUN THIS LAYER
Four steps in the life of an authorized person.
From first vetting to final revocation, access follows the same documented path on every program.
Vet
Confirm U.S. person status and program need before any access request moves forward.
Authorize
Add the person to the program roster and collect the signed data-handling addendum.
Log
Record every session in the environment at the session level, continuously.
Revoke
Run the documented offboarding procedure the day access is no longer needed.
THE ACCESS RULE, IN ONE LINE
The list is short on purpose.
The easiest access model to defend is a small one. We keep the roster for each export-controlled program as short as the work allows, and we review access quarterly instead of waiting for a problem to force the question.
To be plain about scope: ADAPT runs a CMMC Level 2 compliant environment built to the 110 NIST SP 800-171 rev 2 practices. We have not completed a C3PAO assessment, so we do not claim certification. The personnel controls on this page are how the environment is actually staffed and operated today.
Brian Smith, Director of Engineering
TALK TO AN ENGINEER
Tell us what you are building.
Send the program brief. An engineer on our team will read it and respond within one business day. Not a sales coordinator. Not a routing form.