Document Access Rules for Remote and Hybrid Teams
When people work from home, cafes and phones, the office door no longer protects anything. Practical access rules for remote and hybrid teams handling sensitive records.
In an office, a lot of access control happens without anyone noticing: the locked filing cabinet, the building pass, the fact that a client file never leaves the premises. Remote and hybrid work removes all of it. The records are now reached from kitchen tables, shared home computers and phones on trains. The rules that replace the office walls are simple to state: access by role and by matter, from secured accounts and devices, with sharing that is deliberate and visible.
Rule 1: access follows the work, not the team
"Everyone in the team can see the shared drive" was tolerable when everyone sat in one room. Remotely, it means every compromised laptop exposes every record. Give people access to the matters they work on, and to the categories of record their role needs. Review it when people change roles, not just when they leave. We covered the reasoning in insider risk and access control for small teams.
Rule 2: every account has a second factor
Remote work means signing in from many places, which means more exposure to phishing and password reuse. A second factor on every account that can reach client or personal data is the single most effective control available. No exceptions for senior staff. See rolling out two-factor to the whole team.
Rule 3: decide which devices are allowed
- Work devices: encrypted disk, screen lock, automatic updates, and the ability to sign out or wipe remotely.
- Personal devices: if allowed at all, access through the browser or an app rather than downloading files, with a screen lock and current software.
- Shared family computers: not for sensitive records. Say so explicitly.
Rule 4: keep files in the system, not in downloads
The biggest remote leak is quiet: files downloaded to a laptop, emailed to a personal address to print at home, saved to a personal cloud folder. Each copy is outside your controls and outside your retention schedule. Make it easy to view and work on documents where they live, and make the rule clear: no personal email, no personal cloud storage, no local copies unless there is a reason.
Rule 5: share deliberately
External sharing should be a decision, not a default: a named recipient, the least access needed, an expiry where possible, and a record of what was shared with whom. Avoid "anyone with the link" for anything sensitive. Encryption protects data in transit and on disk, but it does not help if the wrong person was given access; encryption at rest vs in transit explains the difference.
Rule 6: mind the physical space
- Screens facing away from windows and housemates; lock the screen when stepping away.
- Calls about sensitive matters not taken in public places.
- Paper printed at home kept to a minimum, stored securely and shredded, not binned.
Rule 7: log and review
You cannot see who is looking over a shoulder at home, but you can see who opened, downloaded and shared what. Use systems that log access, and look at the log periodically, not only after an incident.
Write it down, keep it short
Put these rules on one page, have each person confirm they have read it, and revisit it once a year. Long policies are not read; a short one that people actually follow protects more.