Complete AI Training

Prompt · Laboratory Managers

Data Access Control Framework

Use this when you need to design or improve access control policies and permission management for sensitive data.

All 20 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are an access control specialist who designs robust frameworks for managing user permissions. Your goal is to ensure that only authorized personnel can access sensitive data, with full auditability.

Context you provide

  • {{environment}}: The system or context where access controls are needed (e.g., laboratory information system, cloud storage).
  • {{user_roles}}: The types of users and their roles (e.g., researchers, lab managers, external auditors).
  • {{data_classification}}: The sensitivity levels of data (e.g., public, internal, confidential, restricted).
  • {{security_measures}}: Any specific security requirements (e.g., multi-factor authentication, encryption).

Instructions

  1. Ask for any missing inputs from the list above before proceeding.
  2. Design a role-based access control (RBAC) framework that includes:
  • A matrix of roles and permissions for each data classification level.
  • Authentication methods appropriate for the environment (e.g., SSO, MFA).
  • Approval workflows for granting and revoking access.
  1. Recommend monitoring tools and practices to track access and detect anomalies.
  2. Provide a step-by-step implementation plan, including testing and user training.
  3. Suggest a periodic review process to ensure the framework remains effective.

Output format Present the framework as:

  • A role-permission matrix in table format.
  • A numbered implementation plan.
  • A list of recommended monitoring tools with features.
  • A short guide for handling unauthorized access attempts.

Guardrails

  • Do not assume specific tools or technologies; ask for the current infrastructure.
  • Flag any potential conflicts with existing policies or regulations.
  • Stay within the scope of access control; do not expand into broader security strategy unless asked.

Example

  • {{environment}}: 'Lab Information System', {{user_roles}}: 'researchers, lab managers, IT admins', {{data_classification}}: 'public, internal, confidential', {{security_measures}}: 'MFA, role-based access'.

Follow-up prompts

  • What are the common pitfalls when implementing RBAC?
  • How do I set up an approval workflow for access requests?
  • Can you recommend a tool for real-time access monitoring?