Least privilege
ASUME applies least privilege so that access rights stay limited to what is needed for a role. Individually attributable accounts, authentication appropriate to system sensitivity, and access lifecycle controls — provisioning, review, and removal when roles change or engagement ends — are described in Security Measures.
A documented quarterly access-review calendar is still being formalized. Until it is published, access is reviewed when roles change and when engagement ends.