Access
Access privileges
This page describes the access privileges our consultants request during an engagement, how those privileges are scoped, and how they are removed at handover.
Last updated: 27 July 2026
01Least privilege by default
Consultants request the minimum access required for the agreed scope of work. Where a read-only account is sufficient for discovery or documentation, we ask for read-only access and escalate only for the specific tasks that require it.
02Named accounts, never shared
Every consultant works under an individual named account issued by you. We do not use shared credentials, and we do not create accounts on your systems ourselves unless you explicitly delegate that task in writing.
03Typical privileges requested
- GNS3 server or cluster administrative access for lab builds
- Read-only device access for topology discovery and documentation
- Repository access limited to the automation project branch
- VPN or bastion access restricted to the lab network segment
04Change windows and approvals
Any privileged action affecting a shared or production-adjacent system is performed inside an agreed change window with a named client approver present or on call.
05Revocation
You may revoke any privilege at any time without notice. We ask that all accounts issued to our consultants are disabled within five business days of project handover, and we will confirm in writing once our local copies of any credential material have been destroyed.
06Audit trail
Privileged sessions are logged on your side and summarised in our engagement report. We do not disable, alter or purge logging on client systems.
Questions about this page? Reach us at hello@gns3consulting.example.