Skip to content

Latest commit

 

History

History
49 lines (31 loc) · 3.45 KB

permissionssecurity.md

File metadata and controls

49 lines (31 loc) · 3.45 KB

Permissions and security

1Password

We use 1Password as our tool of choice to manage permissions and logins to all the environments, tools and other confidential information we need for our projects.

Everyone has access to the basic logins that should be available company-wide because we organise them in vaults.

Every project has got a vault to which you will have access if you are working on that project.

We ask everyone to keep the logins tidy and up-to-date and the passwords as strong as possible. 1Password can help you create strong and secure passwords. So remember that if you have signed up for a new tool or created a login that someone else might use, you should add it to the project's vault accordingly.

When you're relocated to another project, your access to the former project's vault will be revoked to avoid leaving stuff floating around.

File storage and file-sharing guidelines

Here you will find our guidelines to use Google Drive, our file storage tool of choice.

Where should we store the documents?

All the documents of the company must be stored in our Google Drive's shared drive called "MarsBased". Google Drive is our central file storage solution.

The folders distribution hasn't changed that much:

  • We still have one folder for each client or project (under Projects);
  • a folder where we store the document templates (Templates);
  • Sales and Marsketing folders;
  • Martian Tapas, where you can find the Martian Tapas recordings;
  • a Design folder with the company logos and images;
  • Organization, which contains the Forecast & Time Off spreadsheet, among other documents;
  • Team includes a short biography of each one of your Martian colleagues (some of them are very funny!);
  • Guides, with books, guides, and training resources;
  • and finally, Martian Days, with company presentations.

Sharing policy

Sharing files in Google Drive is easy but then very difficult to manage. Google Drive doesn't have an option to see which files have been shared outside the company easily. For that reason, we need to think twice before sharing something with someone, freelance, provider or client.

For security reasons, we don't want people from outside the company having access to our folders and documents.

  • Never share an entire folder with someone, unless absolutely necessary. If you have to do it, for any reason, rename the folder adding (shared) at the end to make it easier to see that it has been shared outside MarsBased.
  • Never share anything only with a public link, unless absolutely necessary. It's much better to share with individual people.
  • If the people you want to add don't need editing capabilities, make sure to add them as "viewers" or "commenters".
  • If you add someone as a viewer or commenter, make sure to set an expiration date. Google Drive allows you to define expiration dates up to a year when you share a file with one of these roles. If that person needs access after the expiration date, she/he can make a request again. Sadly, editors can't have an expiration date.
  • If you have doubts or questions before sharing something with someone, ask Jordi and he will clarify.

Naming

We always add the date before a file name to be able to see when was the file created easily. Use the following format: YYYY-MM-DD. We only skip the date in files that are constantly edited and therefore are always up to date or files where the date is completely irrelevant. Some examples are a guide, a Ruby test or a template.