An access policy is a documented rule that defines the conditions under which access may be granted, retained, used or revoked. A policy should identify its scope, owner, decision criteria, exceptions, enforcement method and review frequency.
Examples include “only active finance employees may receive the payment-approver role” and “production administrator access expires after four hours.”