# SP-021 Realtime Collaboration Pattern

Status: published. Release 26.02. Modified 2026-02-06. Licence: CC BY-SA 4.0.

Scope: Security architecture for real-time collaboration platforms including video conferencing, screen sharing, instant messaging, and shared document editing. Addresses authentication, data protection, audit trails, and the unique risks of allowing external participants into collaborative sessions.
Use when: Use this pattern when internal and external partners must collaborate synchronously on shared documents, conduct video or voice conferences, share screens for presentations or demonstrations, or communicate via persistent chat channels. Applicable when the collaboration involves confidential or commercially sensitive information that requires encryption, access control, and audit trails.
Not when: This pattern is not appropriate for ad-hoc, one-time file transfers where the Secure Ad-Hoc File Exchange pattern (SP-019) is more suitable.

## Controls (19, NIST SP 800-53 ids)
- Critical (3): AC-02, AC-17, IA-02
- Important (7): AC-20, AU-02, AU-06, CA-03, IA-04, IR-04, RA-03
- Standard (9): AT-02, AT-03, AU-09, CA-02, CM-03, CP-09, IR-07, RA-05, SI-11

## What each critical control mitigates (3)
- AC-02 Account Management: T-RC-002, T-RC-005, T-RC-009
- AC-17 Remote Access: T-RC-004, T-RC-006
- IA-02 User Identification And Authentication: T-RC-002, T-RC-004, T-RC-006

## Threats and the controls that mitigate them (10)
- T-RC-001 Data Leakage via Unmanaged External Endpoints: AC-20, AT-02, AU-02
- T-RC-002 Unauthorised Access to Collaboration Spaces: AC-02, IA-02, IA-04
- T-RC-003 Malicious File Upload to Shared Workspaces: SI-11, RA-05, AU-06
- T-RC-004 Session Hijacking or Meeting Bombing: IA-02, AC-17, AU-02
- T-RC-005 Stale Guest Accounts with Persistent Access: AC-02, IA-04, CA-02
- T-RC-006 Man-in-the-Middle on Collaboration Streams: AC-17, CA-03, IA-02
- T-RC-007 Shadow IT Collaboration Tool Usage: AT-02, AT-03, CM-03
- T-RC-008 Uncontrolled Meeting Recording and Transcription: AU-02, AU-09, CP-09
- T-RC-009 Privilege Escalation in Collaboration Platform: AC-02, AU-06, RA-05
- T-RC-010 Compliance Failure from Missing Audit Trails: AU-02, AU-06, AU-09, IR-04

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-021/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-021/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 23 KB: /api/v1/patterns/SP-021
- Page for people: /patterns/sp-021/
- Related: SP-001 Client Module; SP-002 Server Module; SP-013 Data Security Pattern; SP-019 Secure Ad-Hoc File Exchange Pattern; SP-020 Email Transport Layer Security (TLS) Pattern; SP-022 Board of Directors Room; SP-025 Advanced Monitoring and Detection

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
