cc6.3-4-001

CC6.3 · D4 · f1

D4
Difficulty
4
Gaps
1
Red Herrings
58%
Avg Score

Task

You are auditing Aurora Labs' SOC 2 Type II compliance for control CC6.3 (Access Authorization). Review the provided evidence to assess whether Aurora Labs effectively authorizes access based on roles, enforces segregation of duties, and applies least privilege principles. Identify any gaps, deficiencies, or areas of concern. Be careful to cross-reference evidence across documents — some apparent issues may have valid exceptions or compensating controls documented elsewhere.

Evidence

Findings

IDTypeSeverityFinding
F-001red_herringlowData analytics role has broad production read access across all collections
The data-analytics role in the MongoDB permissions export grants read access to 10 production collections including financial data (billing, invoices, revenue_records, payment_transactions). This appe...
F-002gaphighFinance employee j.morrison holds billing-service role with write access to financial collections
User j.morrison (James Morrison, Finance department) is assigned the billing-service role, which grants insert and update access to the billing, invoices, and payment_transactions collections. As a Fi...
F-003gapmediumLooker Analytics Platform access certification completed 21 days late
The Q4 2025 access certification for the Looker Analytics Platform (CERT-Q4-2025-006) was due on October 14, 2025, but was not completed until November 4, 2025 — 21 calendar days after the certificati...
F-004gaphighContractor r.santos has no account expiration date despite policy requirement
Contractor Ricardo Santos (r.santos, TechBridge Consulting) has a contract end date of 2025-12-31 but no expiration date set on the database account. Section 6.2 of the data access policy requires tha...
F-005gaphighService account svc-etl-snowflake has production write access with no designated owner
The svc-etl-snowflake service account is assigned the etl-pipeline role, which includes insert and update access to the revenue_records collection in the production database. The account has no design...

Results

ModelProviderScoreRecallPrec.F1GapsReported
Sonnet 4.6Anthropic67%100%50%67%4/48
Opus 4.7Anthropic57%100%40%57%4/410
GPT-5.5OpenAI60%75%50%60%3/46
GPT-4.1OpenAI55%75%43%55%3/47
Haiku 4.5Anthropic67%100%50%67%4/48
GPT-4oOpenAI40%50%33%40%2/46