TierSphere
Privacy Training and Access Controls
This page describes the minimum privacy and security practices expected for personnel who may access protected customer data.
Training Expectations
- Privacy and security training is required during onboarding for employees and contractors with access to production systems or customer data.
- Refresher training must be completed at least annually and whenever material policy changes occur.
- Training must cover confidentiality, FERPA and school-data handling expectations where applicable, incident reporting, phishing awareness, credential hygiene, and least-privilege access practices.
- Personnel must acknowledge that student, teacher, and principal data may be used only for authorized service delivery purposes.
Access Controls
- Production access must be granted only to personnel with a documented business need.
- Privileged access should be approved by an engineering or operations lead and removed promptly when no longer needed.
- Shared credentials are not permitted.
- Access to hosted services must be protected by strong authentication and, where supported, multi-factor authentication.
- API secrets, signing keys, and environment credentials must be stored in managed secret stores or environment configuration, not in source control.
Operational Evidence to Retain
- Onboarding completion record for each authorized team member.
- Annual refresher completion record.
- Access approval or ticket history for privileged environments.
- Access removal record when personnel change roles or leave the company.
Review Cadence
- Review active privileged-access lists at least quarterly.
- Review training materials whenever a new customer privacy requirement or subprocessor is introduced.
Related Policies
Review our Student Data Privacy and Subprocessors and Access Controls pages for related disclosures.