Example, read only. A sample account that shows what finished CMMC looks like.
Safeguard 2 of 15 · AC.L1-b.1.ii
AC.L1-3.1.2 · FAR 52.204-21 (b)(1)(ii) · NIST SP 800-171 3.1.2
Limit information system access to the types of transactions and functions that authorized users are permitted to execute
Even authorized users shouldn't have more access than their job requires, a bookkeeper shouldn't be able to change IT settings.
Admin sprawl is the most common finding. If a bookkeeper or intern is a Global Admin or has root, expect questions. Least-privilege role assignment, documented, is what primes want to see.
Capture: Two screenshots: (1) admin role assignments, (2) a standard user showing no elevated roles.
Access follows least privilege. Estimators can open and edit quotes and drawings; the office admin can read but not change them; only the owner holds admin rights in Microsoft 365. Roles are documented in the access list kept in SharePoint and reviewed each quarter.
You answer in plain English; Charlie writes the official narrative for your System Security Plan.
This is one of 15
Cedar Ridge Machine Works, LLC walked all 15 the same way. The platform explains each one in plain English, tells you exactly what to grab, checks it, and writes the paperwork, and you confirm each one MET. The self assessment stays your act. Start free, or book a call.