Modern organisations rarely have only one type of user. Permanent employees may need access to several business applications, contractors may require temporary access to a limited set of tools, and guests may only need internet connectivity while visiting a site. Applying identical rules to everyone creates unnecessary risk and can make legitimate work harder. A better approach is to design web-access policies around role, device, location and business need. Effective web protection should reduce exposure to malicious or unsuitable content without blocking the services people genuinely require.
Begin With User Groups, Not One Universal Rule
A blanket policy may allow too much access for external users while restricting employees who need specialist cloud services. Begin by separating users according to how they work and the information they handle.
Permanent employees can be divided into roles such as finance, sales, engineering or customer support. Contractors should be grouped according to their project and contract duration rather than added to a general employee policy. Guest users should remain isolated from business systems unless there is a documented reason for access.
The NCSC recommends role-based access control and permissions limited to the resources required for a particular role. This supports the principle of least privilege and reduces the potential impact of a compromised identity.
Define What Each Group Needs to Do
Policies should support work rather than simply block broad website categories. Department managers can help identify which websites, SaaS platforms, upload functions and collaboration tools are required.
An access review should establish:
- Applications needed for regular responsibilities
- Data users may upload or download
- Whether personal cloud storage is permitted
- Activities requiring additional approval
- When should access begin and expire
This prevents policies from being built around assumptions. It also makes exception requests easier to evaluate because expected use has already been documented.
Apply Stronger Controls to Higher-Risk Activity
Not all web activity carries the same level of risk. Visiting a public information page is different from uploading customer records to an unapproved file-sharing service.
Employees handling financial, legal or personal information may require tighter controls on uploads and unsanctioned applications. Contractors may be permitted to use an approved project platform but prevented from transferring files to personal accounts. Guests may receive internet access while remaining separated from internal resources. Policies should therefore become more restrictive as the sensitivity of the data or action increases.
Use Context to Make Better Access Decisions
A user’s role is important, but it should not be the only factor. Device ownership, location and current risk can also influence whether access is allowed. An employee using a managed device from a recognised office location may receive broader access than the same account signing in from an unknown device. A contractor’s access may be limited to agreed working hours or the project period. High-risk downloads may require additional checks even when the website itself is permitted.
A well-designed CASB security layer can provide visibility into cloud-application use and help control uploads, downloads and access to unsanctioned services. However, it should support the policy rather than replace the organisation’s responsibility to define acceptable behaviour.
Build a Controlled Exception Process
No policy will anticipate every legitimate requirement. The answer is not to weaken the rules whenever someone encounters a restriction, but to create a documented exception process. Requests should include the business reason, required duration, application owner and type of data involved.
Higher-risk exceptions may need approval from security, data protection or senior management. Temporary access should expire automatically rather than remain active indefinitely. Recording exceptions can also reveal recurring business needs. When several employees request the same approved service, the standard policy may need to be reviewed.
See also: Component Obsolescence in Defence Cable Programmes: Protecting Supply, Compliance and Traceability
Review Joiners, Movers and Leavers
Access rules lose value when identity records are inaccurate. New starters should receive permissions based on an approved role rather than by copying another employee’s account. People changing departments should lose unnecessary access as well as gain new permissions.
Contractor accounts need explicit end dates, while guest access should normally be short-lived. The NCSC also advises organisations to apply least privilege to third parties and retain visibility of the permissions they receive. Regular reviews help identify dormant accounts, excessive privileges and rules that no longer reflect how teams operate.
Measure Whether the Policy Works
Monitor blocked activity, exception requests, newly discovered cloud applications and repeated policy violations. A high number of blocks may indicate risky behaviour, but it may also expose a poorly designed rule that interrupts legitimate work. Useful measures include unapproved applications detected, expired contractor accounts, repeated risky uploads and the time needed to approve exceptions.
Conclusion
Web-access policies should reflect the differences between employees, contractors and guests rather than forcing every user into one set of rules. Starting with business roles, applying least privilege and using contextual controls can reduce exposure while preserving productivity.
Regular reviews, controlled exceptions and accurate joiner, mover and leaver processes keep permissions aligned with real responsibilities. When web controls are designed around people, data and risk, organisations gain stronger protection without turning everyday internet use into an obstacle.





