User access review pack
Reviews user and service access against people records, role definitions, and separation-of-duties rules, then produces an evidence-ready access matrix and revocation list. Use for quarterly access recertification, joiner-mover-leaver checks, privileged access review, orphaned accounts, and access audit preparation.
Published Aug 21, 2026 · Updated Aug 26, 2026
Requirements
Map access-export fields and account types to the company identity model. Add current role and separation-of-duties definitions to the scope. Set review period, severity labels, and evidence-retention requirements.
Skill document
The full SKILL.md your agent reads and follows.
User access review pack
Purpose
Prepare a periodic review of logical access so each account can be tied to a person, role, system, and business need. Produce a review matrix, documented exceptions, and a prioritized revocation list without asserting that any access has actually been changed.
Scope
User, service, shared, and privileged accounts in the supplied system exports; employment status, role assignments, and separation-of-duties rules. Excluded: changing accounts, contacting managers, or making final access decisions.
Data basis
- Access exports with account, system, group, role, privilege, and last-use fields.
- Current people table with employment status, team, manager, and role.
- Role and entitlement catalogue, separation-of-duties rules, and prior review findings.
Result
An access review matrix with one row per account-entitlement relationship, a findings sheet with evidence citations, and a manager attestation document grouped by owner.
Quality criteria
- Every active account has an identity or an explicit unresolved ownership status.
- Every finding cites the source export, row, or rule.
- Privileged, shared, departed-user, and SoD cases are separately labelled.
- Counts in the summary reconcile to the matrix.
Instructions
Preserve source identifiers exactly. Treat missing last-use data as unknown, not inactive. Separate a policy exception from a data defect. Rank findings using the company risk rules; where none exist, use critical for departed or unexplained privileged access, high for SoD conflicts, and review for other anomalies, stating that the fallback was used. Do not infer approval from a manager name.
Adapt before use
- Map export columns and account types to the company identity and access model.
- Add the current role catalogue and separation-of-duties rules to the scope.
- Define review period, privileged-access criteria, and severity labels.
- Specify the evidence-retention and attestation format expected by the audit owner.
Related skills
- Access provisioning checklist
Converts employee roles and lifecycle events into a system-by-system provisioning or deprovisioning checklist with approvals, dependencies, and audit evidence fields. Use for joiner, mover, leaver, role-change, access-request, and identity-control preparation.
- Audit evidence pack
Organizes audit requests into evidence tests, evaluates supplied documents for coverage and period, and produces a traceable evidence tracker with control narratives and gaps. Use for SOC, ISO, internal control, customer audit, certification, and audit-readiness preparation.
- Backup and recovery verification
Checks backup coverage, retention, failures, and recovery-test evidence against system criticality and recovery objectives, then produces a verification report and remediation list. Use for backup audits, disaster-recovery readiness, RTO/RPO reviews, resilience checks, and recurring IT control evidence.
- Change release record
Turns a proposed production change into a structured risk, test, approval, rollback, and verification record with traceable evidence. Use for change management, release readiness, deployment review, CAB preparation, rollback planning, and audit documentation.