$4,154.72
$1,133.31
$796.02
$794.07
$793.28
$778.74
$793.31
$784.30
$784.47
$3,180.77
$3,150.02
$3,123.54
$2,843.36
$59.99
$49.99
$119.99
$99.99
$74.99
$74.99
$49.99
$119.99
$99.99
$32.20
$35.99
$35.99
$37.99
$32.79
$35.99
$34.29
$34.99
$99.65
$60.52
$82.67
$91.49
$591.52
$709.85
$338.90
$643.20
$1,026.84
$3,179.99
$251.99
$455.99
$335.96
$10.50
$16.50
$35.00
$35.00
$34.00
$73.99
$143.98
$87.59
$120.00
$26.92
$46.26
$30.89
$78.41
$115.18
$35.00
$34.00
TieredUp Tech, Inc.
Version 1.0 — Effective May 24, 2026
Next Review: May 24, 2027
This Access Control Policy establishes the rules and procedures TieredUp Tech, Inc. ("the Company") follows to control who can access Company information systems, what level of access each person receives, and how access is granted, reviewed, and revoked. This Policy supplements the Information Security Policy and applies to all systems described therein.
This Policy applies to:
The Company applies the following principles to all access decisions:
| Category | Description | Examples |
|---|---|---|
| Administrative | Full or elevated rights to a system; can change configuration, view all data, manage other users | cPanel admin, Hub admin, Shopify Admin, Plaid Dashboard, GitHub org owner |
| Operational | Limited business access for daily work; cannot change system configuration | RepairDesk technician, RepairDesk POS user |
| Service / API | Programmatic access used by automated systems | Plaid access tokens, Shopify Admin API tokens, RepairDesk API keys, GitHub deploy keys |
| Read-only | View-only access for monitoring or reporting | Reserved for future use |
| Person | Role | Access Granted |
|---|---|---|
| Coby Poluk | President & sole administrator | Administrative on all systems in Information Security Policy §1 |
| Lindsey Poluk | VP / phone technician | Operational: RepairDesk user account, dedicated OS user on shop POS computer |
| Charles Bray | General Manager | Operational: RepairDesk user account, dedicated OS user on shop POS computer |
No other persons have system access. Future grants must follow the request and approval procedure in Section 7.
Unique identity. Every person accessing Company systems must do so under a unique account assigned to that individual. Account sharing is prohibited.
Password requirements. All passwords for Company systems must meet these minimums:
Multi-Factor Authentication (MFA). MFA is required on every system that supports it, including all systems listed in Information Security Policy §7. The Company prefers TOTP authenticator apps; SMS-based MFA is used only when no TOTP option is available.
Recovery codes. MFA recovery codes are stored in the password manager and are not shared.
Session management.
All access requests follow this procedure:
The Information Security Officer conducts an access review every quarter (within 30 days of each calendar quarter end). The review covers:
Findings are recorded in the quarterly self-audit log maintained by the Information Security Officer.
When a person's access is no longer required (separation, role change, project completion, or contract end), the following steps are executed within 24 hours:
Service accounts and API credentials (Plaid access tokens, Shopify Admin API tokens, RepairDesk API keys, GitHub tokens, etc.) follow these rules:
Physical access to the Company's premises at 1812 N 16th St, Orange, TX 77630 is controlled as follows:
Administrative access to Company systems from off-premises locations is permitted only when:
Systems are configured to lock accounts after repeated failed login attempts where supported:
Account lockouts are investigated as potential security events when they occur on administrative accounts.
The Information Security Officer holds the highest level of privilege in all Company systems. To reduce risk of privilege misuse:
Any deviation from this Policy must be documented as an exception:
Violations of this Policy may result in:
This Policy is reviewed annually on or before the effective-date anniversary, and after any significant change to systems, personnel, or scope.
For questions about this Policy or access requests:
Coby Poluk, President & Information Security Officer
TieredUp Tech, Inc.
1812 N 16th St
Orange, TX, 77630, US
Email: security@tiereduptech.com
This Policy is published at https://tiereduptech.com/pages/access-control-policy and is the authoritative version.
At TieredUp Tech, Inc., we deliver top-quality repairs and custom-built computer systems, ensuring every device performs at its best for our valued customers.
!