_private/qwestly-private-docs/SOC2/evidence/access-list/access-review-q3-2026.md
Table of Contents
Qwestly Quarterly Access Review - Q3 2026
Review Date: July 20, 2026 Review Period: Q3 2026 (Jul - Sep) Reviewer: Dominick Pham, CTO Total Users: 5 Next Review: October 20, 2026
Executive Summary
This document serves as evidence of a completed periodic user access review for Qwestly's critical systems. All user access was validated against current job roles and responsibilities. No unauthorized or inappropriate access was identified. Access to decommissioned systems (Supabase) has been documented.
1. Vercel
System: Vercel - Hosting and Deployment Auth Method: Google Workspace SSO Review Date: July 20, 2026
| Name | Role | Justification | Action | |
|---|---|---|---|---|
| Dominick Pham | dominick@qwestly.com | Owner | CTO - manages all deployments, projects, billing | Retained |
| Adam Boender | adam@qwestly.com | Owner | CEO - backup admin, billing access | Retained |
| David | david@qwestly.com | Member | Engineering - deploys and manages projects | Retained |
| Vela | vela@qwestly.com | Member | Engineering - deploys and manages projects | Retained |
| Mikelle | mikelle@qwestly.com | Viewer | Engineering - view preview deployments and project info | Retained |
Review Notes: All access remains appropriate. No changes required.
2. MongoDB Atlas
System: MongoDB Atlas - Primary Database Auth Method: MFA (TOTP) + IP Allowlisting Review Date: July 20, 2026
| Name | Role | Justification | Action | |
|---|---|---|---|---|
| Dominick Pham | dominick@qwestly.com | Organization Owner | CTO - database administration, schema management | Retained |
| Adam Boender | adam@qwestly.com | Organization Owner | CEO - backup admin, billing access | Retained |
| David | david@qwestly.com | Project Data Access | Engineering - data access for development and debugging | Retained |
| Vela | vela@qwestly.com | Project Data Access | Engineering - data access for development and debugging | Retained |
Review Notes: Atlas network access restricted to Vercel production IP ranges for production cluster. Development cluster has separate access controls. No changes required.
3. GitHub
System: GitHub - Source Code, CI/CD, Security Scanning Auth Method: MFA Review Date: July 20, 2026
| Name | Role | Justification | Action | |
|---|---|---|---|---|
| Dominick Pham | dominick@qwestly.com | Admin | CTO - repository management, branch protection, CI/CD | Retained |
| Adam Boender | adam@qwestly.com | Admin | CEO - backup admin | Retained |
| David | david@qwestly.com | Write | Engineering - code contribution, PR management | Retained |
| Vela | vela@qwestly.com | Write | Engineering - code contribution, PR management | Retained |
| Mikelle | mikelle@qwestly.com | Write | Engineering - code contribution, PR management | Retained |
Review Notes: All team members have appropriate access. Branch protection rules enforce PR reviews on main branch. All users authenticate via MFA. No changes required.
4. Auth0
System: Auth0 - User Authentication Provider Auth Method: Google Workspace SSO + MFA Review Date: July 20, 2026
| Name | Role | Justification | Action | |
|---|---|---|---|---|
| Dominick Pham | dominick@qwestly.com | Admin | CTO - authentication configuration, tenant management | Retained |
| Adam Boender | adam@qwestly.com | Admin | CEO - backup admin | Retained |
Review Notes: Restricted to admin only. No developer access to production Auth0 tenant. Development tenant is separate. No changes required.
5. AWS S3
System: AWS S3 - Log Archive and Document Storage Auth Method: IAM + MFA Review Date: July 20, 2026
| Name | Role | Justification | Action | |
|---|---|---|---|---|
| Dominick Pham | dominick@qwestly.com | Admin | CTO - infrastructure management, log archive access | Retained |
| Adam Boender | adam@qwestly.com | Admin | CEO - backup admin | Retained |
Review Notes: Production buckets restricted via IAM policies. Log archive bucket (qwestly-logs) has 90-day retention policy. No changes required.
6. Google Workspace
System: Google Workspace - Identity Provider, Email Auth Method: SSO (IdP) Review Date: July 20, 2026
| Name | Role | Justification | Action | |
|---|---|---|---|---|
| Dominick Pham | dominick@qwestly.com | Super Admin | CTO - IdP management, security configuration | Retained |
| Adam Boender | adam@qwestly.com | Super Admin | CEO - IdP management | Retained |
| David | david@qwestly.com | User | Engineering - email, calendar, docs | Retained |
| Vela | vela@qwestly.com | User | Engineering - email, calendar, docs | Retained |
| Mikelle | mikelle@qwestly.com | User | Engineering - email, calendar, docs | Retained |
Review Notes: SSO enforcement enabled. MFA required for all accounts. No external sharing of confidential documents enabled. No changes required.
7. Additional Systems
| System | Access | Review Status |
|---|---|---|
| 1Password | All team members via MFA | Appropriate - credential sharing limited to relevant vaults |
| Slack | All team members via SSO | Appropriate - no guest accounts |
| PostHog | Dominick (Admin), David/Vela/Mikelle (Member) | Appropriate |
| LangSmith | Dominick (Admin) | Appropriate - LLM observability only |
| Asana | All team members via SSO | Appropriate |
| SendGrid | Dominick (Admin) via api-python gateway | Appropriate - API key access only |
| Supabase | Dominick (Owner) | DEACTIVATED - legacy system, being phased out |
Summary of Actions
| Action | Count | Details |
|---|---|---|
| Access retained | 28 | All appropriate |
| Access upgraded | 0 | None required |
| Access removed | 0 | None required |
| Systems deactivated | 1 | Supabase (legacy, phased out) |
Reviewer Sign-off
Reviewer: Dominick Pham, CTO Date: July 20, 2026 Signature: Access review completed. All user access validated against current job roles and responsibilities. No unauthorized access detected. Access to Supabase has been documented as deactivated.
Sponsor Acknowledgement: Adam Boender, CEO Date: July 20, 2026
Document Classification: Internal Use - SOC2 Audit Evidence Document Owner: Dominick Pham, CTO