---
name: user-access-review-pack
description: Reviews user and service access against people records, role definitions, and separation-of-duties rules, then produces an evidence-ready access matrix and revocation list. Use for quarterly access recertification, joiner-mover-leaver checks, privileged access review, orphaned accounts, and access audit preparation.
license: Apache-2.0
metadata:
  adlass.categories: "it-security/access-identity, it-security/audit-evidence"
  adlass.industries: ""
  adlass.tags: "access-review, identity, privileges, audit, recertification, accounts"
  adlass.adaptation: "mapping"
  adlass.source: "original"
  adlass.version: "1"
---

# User access review pack

## Purpose

Prepare a periodic review of logical access so each account can be tied to a person, role, system, and business need. Produce a review matrix, documented exceptions, and a prioritized revocation list without asserting that any access has actually been changed.

## Scope

User, service, shared, and privileged accounts in the supplied system exports; employment status, role assignments, and separation-of-duties rules. **Excluded:** changing accounts, contacting managers, or making final access decisions.

## Data basis

- Access exports with account, system, group, role, privilege, and last-use fields.
- Current people table with employment status, team, manager, and role.
- Role and entitlement catalogue, separation-of-duties rules, and prior review findings.

## Result

An access review matrix with one row per account-entitlement relationship, a findings sheet with evidence citations, and a manager attestation document grouped by owner.

## Quality criteria

- Every active account has an identity or an explicit unresolved ownership status.
- Every finding cites the source export, row, or rule.
- Privileged, shared, departed-user, and SoD cases are separately labelled.
- Counts in the summary reconcile to the matrix.

## Instructions

Preserve source identifiers exactly. Treat missing last-use data as unknown, not inactive. Separate a policy exception from a data defect. Rank findings using the company risk rules; where none exist, use critical for departed or unexplained privileged access, high for SoD conflicts, and review for other anomalies, stating that the fallback was used. Do not infer approval from a manager name.

## Adapt before use

- Map export columns and account types to the company identity and access model.
- Add the current role catalogue and separation-of-duties rules to the scope.
- Define review period, privileged-access criteria, and severity labels.
- Specify the evidence-retention and attestation format expected by the audit owner.
