Aguardic logoAguardic

SOC 2 Access Controls

by AguardicOfficial·v1.0.0

Enforce SOC 2 Type II access control and credential management requirements.

About This Policy Template

SOC 2 compliance policy that enforces access control requirements across Trust Services Criteria. Monitors for credential sharing, unauthorized access patterns, exposed API keys, default credentials, and permission escalation indicators. Essential for B2B SaaS companies demonstrating security controls to enterprise customers.

Policy Rules(3)

High Severity

(3)

API Key Exposure

Detect exposed API keys and tokens

Rule

Credential Sharing Detection

Detect potential credential sharing in communications

Rule

Default Credentials Detection

Detect default or common credentials that should be changed

Rule

Enforcement by Integration

What happens when a violation is detected, based on the enforcement mode and integration type.

IntegrationBlockApprovalWarnMonitor
Version Control
GitHub, GitLab, Bitbucket
Fail check run / merge request statusPending check run — held for reviewNeutral check run / comment on PRPass check run (silent)
Email — Gmail
Gmail
Quarantine label; + violation label (outbound)Quarantine label — held for reviewAdd warning labelLog only
Email — Outlook
Outlook
Move to quarantine folder; + flag (outbound)Move to quarantine — held for reviewFlag + categorizeLog only
Messaging
Slack, Teams
Post violation warning in channelPost 'held for review' warningPost warning in channelLog only
Storage
Google Drive, Dropbox, OneDrive
Move file to quarantine folderQuarantine file — held for reviewLog onlyLog only
AI Proxy
OpenAI, Anthropic, Gemini, MCP, Agent
Block request (return 403)Hold request — return review IDAllow request + audit trailLog only
API
REST API
Return BLOCK outcome (client decides)Return APPROVAL_REQUIRED + poll URLReturn WARN outcomeLog only

Version History

1 version published

v1.0.0Active2/23/2026

Initial release

SOC 2 with AI questions?

Answer the AI-specific SOC 2 questions with controls Aguardic enforces

Try the tool

Ready to Install SOC 2 Access Controls?

Get started with pre-built governance policies in minutes.