Production systems process real customer data and live financial activity. Access to them must be narrow enough to limit harm, but practical enough for authorized employees and services to operate, support and recover the bank.

01

Production is separated from development and testing

Banks distinguish live environments from the places where software is built and tested. Separation reduces the chance that experimental code, test credentials or unapproved data changes reach customer-facing services.

The boundary can include different accounts, networks, credentials, datasets and release processes. A developer may be able to prepare a change without having standing authority to alter the live system directly.

02

Identity and least privilege define normal access

Each employee, application and automated service should have an attributable identity. Authorization then limits that identity to the systems, data and actions needed for its assigned responsibility.

This is the principle of least privilege. It reduces exposure from mistakes and compromised credentials while making logs more meaningful because actions are connected to a specific person or service rather than a widely shared account.

03

Privileged work receives stronger controls

Administrative access can change configurations, view sensitive information or affect large volumes of activity. Banks may require stronger authentication, additional approval, a managed workstation and time-limited access for these higher-impact actions.

Emergency access can be necessary during an outage, but it should not become an invisible shortcut. A defined break-glass process records why access was granted, narrows its duration and triggers review after the immediate need ends.

04

Change controls separate preparation from release

Code and configuration changes move through review, testing and authorized deployment. Segregating key steps helps prevent one person from creating, approving and releasing a material change without independent evidence.

Automation can make releases more consistent, but the pipeline itself becomes a sensitive production pathway. Its permissions, approvals, secrets and logs need the same disciplined governance as direct administrative access.

05

Monitoring and recertification keep access current

Teams monitor unusual sign-ins, privilege changes, sensitive queries and actions outside expected patterns. Alerts are connected to incident procedures so the bank can investigate and revoke access when necessary.

Periodic reviews confirm that access still matches current responsibilities. Transfers, vendor changes and terminated relationships should trigger prompt updates rather than waiting for the next scheduled review.

Sources

Read the primary material

Banking Explained prioritizes regulators, official publications and first-party announcements.