Access provisioning checklist
Converts employee roles and lifecycle events into a system-by-system provisioning or deprovisioning checklist with approvals, dependencies, and audit evidence fields. Use for joiner, mover, leaver, role-change, access-request, and identity-control preparation.
Veröffentlicht 21. Aug. 2026 · Aktualisiert 26. Aug. 2026
Voraussetzungen
Map role, system, entitlement, and person fields. Add approval, exception, handover, evidence, and timing rules. Define lifecycle event terminology and required document owners.
Skill-Dokument
Das vollständige SKILL.md, das dein Agent liest und befolgt.
Access provisioning checklist
Purpose
Translate a person’s role and lifecycle event into an ordered, reviewable access plan. Make standard access, exceptional rights, approvals, handoffs, and completion evidence explicit without performing any account action.
Scope
Joiner, mover, leaver, and access-change records; role-access matrix; system catalogue; approval rules; data handoff requirements. Excluded: creating, changing, or disabling accounts and making approvals.
Data basis
- Person and lifecycle event record.
- Role-to-access matrix and system catalogue.
- Approval policy, exception rules, and offboarding handover requirements.
Result
A provisioning checklist, approval-request document, and—when applicable—a deprovisioning order with dependencies and evidence fields.
Quality criteria
- Every system in the role package is represented exactly once.
- Exceptional access has a business reason and approval role.
- Offboarding order preserves documented handover dependencies.
- No step implies that a change was executed.
Instructions
Use the matrix as the authority for standard access. Do not infer access from a job title when no role mapping exists. Keep event date, effective date, and requested completion date distinct. Flag conflicts between role packages and system rules. Preserve the original person and system identifiers.
The review should make the population, calculation basis, and exception treatment understandable to a second operator. Preserve source identifiers in every working table, and state the effect of missing evidence on the decision. A reviewer must be able to reproduce each material result from the cited rows, clauses, dates, or policy rules. Where two sources disagree, show both values and explain which source was treated as authoritative.
Use the outputs as review workpapers: retain the source locator beside every material value, and keep planned action separate from completed evidence. The final document must identify the consequence of each gap for the relevant operational or control decision.
Adapt before use
- Map role, system, entitlement, and person fields to company records.
- Add approval, exception, handover, and evidence rules.
- Define timing conventions for joiners, movers, and leavers.
Verwandte Skills
- Audit evidence pack
Organizes audit requests into evidence tests, evaluates supplied documents for coverage and period, and produces a traceable evidence tracker with control narratives and gaps. Use for SOC, ISO, internal control, customer audit, certification, and audit-readiness preparation.
- Backup and recovery verification
Checks backup coverage, retention, failures, and recovery-test evidence against system criticality and recovery objectives, then produces a verification report and remediation list. Use for backup audits, disaster-recovery readiness, RTO/RPO reviews, resilience checks, and recurring IT control evidence.
- Change release record
Turns a proposed production change into a structured risk, test, approval, rollback, and verification record with traceable evidence. Use for change management, release readiness, deployment review, CAB preparation, rollback planning, and audit documentation.
- Incident postmortem
Reconstructs a technical incident from timelines, tickets, chats, monitoring evidence, and impact data, then produces a blameless postmortem with causes, gaps, and owned corrective actions. Use for service outages, security incidents, production failures, incident reviews, and lessons-learned reports.