Notion access control & privilege security checks
Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.
On Notion, Black Cat runs 6 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Notion connector needs.
Checks (6)
severity: medium Guest User Sprawl fix difficulty: easy #
Remove unnecessary guest users from the Notion workspace
- Open Notion and click Settings & Members in the left sidebar
- Select the Members tab and switch to the Guests section
- Review each guest user and their page access
- Click the three-dot menu next to any guest who no longer needs access
- Select Remove from workspace
- Repeat for all unnecessary guest accounts
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Member Without Email fix difficulty: easy #
Ensure all workspace members have a valid email address configured
- Open Notion and click Settings & Members in the left sidebar
- Select the Members tab and locate the flagged member
- Contact the member and ask them to update their Notion account email under My account > Email
- If the account cannot be attributed to a real person, consider removing it
- For managed workspaces with SAML SSO, ensure the IdP provides a valid email attribute
- Re-verify the member record after the email is updated
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low Bot Without Description fix difficulty: easy #
Add a description to the Notion integration to document its purpose
- Navigate to https://www.notion.so/my-integrations in your browser
- Select the integration that is missing a description
- Click Edit integration
- Fill in the Description field with the integration's purpose and owner
- Save the changes
Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low Excessive Workspace Members fix difficulty: medium #
Review workspace membership and remove unnecessary members to reduce access sprawl
- Open Notion and click Settings & Members in the left sidebar
- Select the Members tab and review the full member list
- Identify members who no longer need access (departed employees, inactive accounts)
- Remove unnecessary members via the three-dot menu
- Consider implementing group-based access controls instead of individual memberships
- Document the membership review in your access governance process
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: medium Excessive Guest Ratio fix difficulty: medium #
Review and reduce guest accounts when they exceed 50% of workspace membership
- Open Notion and click Settings & Members in the left sidebar
- Select the Members tab and switch to the Guests section
- Review each guest user and verify they still need access
- Remove guests who no longer require access via the three-dot menu
- For recurring external collaborators, consider converting them to full members with appropriate permissions
- Disable guest invitations at the workspace level if external access is not needed
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2
severity: low Bot User Without Name fix difficulty: easy #
Configure a descriptive name for bot users to enable proper auditing
- Navigate to https://www.notion.so/my-integrations in your browser
- Identify the integration corresponding to the unnamed bot user
- Click Edit integration
- Set a descriptive name that identifies the integration's purpose and owner
- Save the changes
- Verify the bot user now appears with the updated name in the workspace member list
Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2