Skip to content

Notion access control & privilege security checks

Admin roles, standing privileges, permission scopes and policy enforcement — the settings that decide how much damage one compromised account can do.

On Notion, Black Cat runs 6 checks in this area on every scan. Each one below lists its severity, how to fix it, and the compliance controls it satisfies where a control applies. See what access the Notion connector needs.

Checks (6)

severity: medium Guest User Sprawl fix difficulty: easy #

Remove unnecessary guest users from the Notion workspace

  1. Open Notion and click Settings & Members in the left sidebar
  2. Select the Members tab and switch to the Guests section
  3. Review each guest user and their page access
  4. Click the three-dot menu next to any guest who no longer needs access
  5. Select Remove from workspace
  6. Repeat for all unnecessary guest accounts

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Member Without Email fix difficulty: easy #

Ensure all workspace members have a valid email address configured

  1. Open Notion and click Settings & Members in the left sidebar
  2. Select the Members tab and locate the flagged member
  3. Contact the member and ask them to update their Notion account email under My account > Email
  4. If the account cannot be attributed to a real person, consider removing it
  5. For managed workspaces with SAML SSO, ensure the IdP provides a valid email attribute
  6. Re-verify the member record after the email is updated

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Bot Without Description fix difficulty: easy #

Add a description to the Notion integration to document its purpose

  1. Navigate to https://www.notion.so/my-integrations in your browser
  2. Select the integration that is missing a description
  3. Click Edit integration
  4. Fill in the Description field with the integration's purpose and owner
  5. Save the changes

Vendor docs ↗

Satisfies: ISO 27001:2022 A.5.15 SOC 2 Type II CC6.1 CIS Controls v8 CIS-06.1 NIST CSF 2.0 PR.AA-05 GDPR (SaaS Security) GDPR-25.2 HIPAA (SaaS Security) HIPAA-312.a NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Excessive Workspace Members fix difficulty: medium #

Review workspace membership and remove unnecessary members to reduce access sprawl

  1. Open Notion and click Settings & Members in the left sidebar
  2. Select the Members tab and review the full member list
  3. Identify members who no longer need access (departed employees, inactive accounts)
  4. Remove unnecessary members via the three-dot menu
  5. Consider implementing group-based access controls instead of individual memberships
  6. Document the membership review in your access governance process

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: medium Excessive Guest Ratio fix difficulty: medium #

Review and reduce guest accounts when they exceed 50% of workspace membership

  1. Open Notion and click Settings & Members in the left sidebar
  2. Select the Members tab and switch to the Guests section
  3. Review each guest user and verify they still need access
  4. Remove guests who no longer require access via the three-dot menu
  5. For recurring external collaborators, consider converting them to full members with appropriate permissions
  6. Disable guest invitations at the workspace level if external access is not needed

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

severity: low Bot User Without Name fix difficulty: easy #

Configure a descriptive name for bot users to enable proper auditing

  1. Navigate to https://www.notion.so/my-integrations in your browser
  2. Identify the integration corresponding to the unnamed bot user
  3. Click Edit integration
  4. Set a descriptive name that identifies the integration's purpose and owner
  5. Save the changes
  6. Verify the bot user now appears with the updated name in the workspace member list

Vendor docs ↗

Satisfies: NIS2 Directive NIS2-21.i.1 DORA (SaaS Security) DORA-9.2

More Notion checks

The information on this page is provided for general informational purposes and is believed to be accurate as of its most recent update. Product names, logos, and trademarks are the property of their respective owners and are used for identification purposes only; their use does not imply any affiliation with or endorsement by those owners. Descriptions of third-party applications and of compliance frameworks are based on publicly available documentation and may change over time.

See these checks run on your stack

Start a free 14-day trial — no credit card required.

Start Free Trial