Skip to main content

TierSphere

Privacy Training and Access Controls

This page describes the minimum privacy and security practices expected for personnel who may access protected customer data.

Training Expectations

  • Privacy and security training is required during onboarding for employees and contractors with access to production systems or customer data.
  • Refresher training must be completed at least annually and whenever material policy changes occur.
  • Training must cover confidentiality, FERPA and school-data handling expectations where applicable, incident reporting, phishing awareness, credential hygiene, and least-privilege access practices.
  • Personnel must acknowledge that student, teacher, and principal data may be used only for authorized service delivery purposes.

Access Controls

  • Production access must be granted only to personnel with a documented business need.
  • Privileged access should be approved by an engineering or operations lead and removed promptly when no longer needed.
  • Shared credentials are not permitted.
  • Access to hosted services must be protected by strong authentication and, where supported, multi-factor authentication.
  • API secrets, signing keys, and environment credentials must be stored in managed secret stores or environment configuration, not in source control.

Operational Evidence to Retain

  • Onboarding completion record for each authorized team member.
  • Annual refresher completion record.
  • Access approval or ticket history for privileged environments.
  • Access removal record when personnel change roles or leave the company.

Review Cadence

  • Review active privileged-access lists at least quarterly.
  • Review training materials whenever a new customer privacy requirement or subprocessor is introduced.

Related Policies

Review our Student Data Privacy and Subprocessors and Access Controls pages for related disclosures.