Using expiry
Set an end date on data rules when the access has a temporary purpose.
When to use this
- Use it for projects with a start and an end.
- Use it for investigations, one-off audits, or temporary cover.
- Use it when the access is sensitive and should be revisited automatically.
Before you start
- Decide on the date or period needed.
- Confirm whether the user or group will need to renew the access afterwards.
- Tell the requester about the agreed deadline.
Step by step
- When creating or editing a rule, find the expiry option.
- Choose the access's end date.
- Check that the deadline matches the purpose.
- Simulate the rule where available.
- Save it and tell the requester the deadline.
What happens next
- The access stops applying when the expiry is reached.
- The rule stays traceable for auditing.
- The user has to request a renewal if they still need the data.
Common errors
- Too short an expiry: it can interrupt work in progress.
- Too long an expiry: it raises exposure unnecessarily.
- Forgetting to communicate the deadline: it comes as a surprise when the access ends.
Good practice
- Use standardized deadlines per request type.
- Review rules with no expiry more often.
- Prefer renewing with justification over granting an indefinite period.
Next steps
Was this page helpful?
Report a problem on this pageDo not send passwords, keys, tokens, or customer data.