Volver a la biblioteca

User access review pack

Reviews user and service access against people records, role definitions, and separation-of-duties rules, then produces an evidence-ready access matrix and revocation list. Use for quarterly access recertification, joiner-mover-leaver checks, privileged access review, orphaned accounts, and access audit preparation.

por adlass TemplatesVersión 1Usa herramientas de adlassUniversal

Publicado 21 de ago de 2026 · Actualizado 26 de ago de 2026

Útil · 0Ver SKILL.md sin formato

Requisitos

Map access-export fields and account types to the company identity model. Add current role and separation-of-duties definitions to the scope. Set review period, severity labels, and evidence-retention requirements.

Documento de la habilidad

El SKILL.md completo que tu agente lee y sigue.

User access review pack

Purpose

Prepare a periodic review of logical access so each account can be tied to a person, role, system, and business need. Produce a review matrix, documented exceptions, and a prioritized revocation list without asserting that any access has actually been changed.

Scope

User, service, shared, and privileged accounts in the supplied system exports; employment status, role assignments, and separation-of-duties rules. Excluded: changing accounts, contacting managers, or making final access decisions.

Data basis

  • Access exports with account, system, group, role, privilege, and last-use fields.
  • Current people table with employment status, team, manager, and role.
  • Role and entitlement catalogue, separation-of-duties rules, and prior review findings.

Result

An access review matrix with one row per account-entitlement relationship, a findings sheet with evidence citations, and a manager attestation document grouped by owner.

Quality criteria

  • Every active account has an identity or an explicit unresolved ownership status.
  • Every finding cites the source export, row, or rule.
  • Privileged, shared, departed-user, and SoD cases are separately labelled.
  • Counts in the summary reconcile to the matrix.

Instructions

Preserve source identifiers exactly. Treat missing last-use data as unknown, not inactive. Separate a policy exception from a data defect. Rank findings using the company risk rules; where none exist, use critical for departed or unexplained privileged access, high for SoD conflicts, and review for other anomalies, stating that the fallback was used. Do not infer approval from a manager name.

Adapt before use

  • Map export columns and account types to the company identity and access model.
  • Add the current role catalogue and separation-of-duties rules to the scope.
  • Define review period, privileged-access criteria, and severity labels.
  • Specify the evidence-retention and attestation format expected by the audit owner.

Habilidades relacionadas

  • Access provisioning checklist

    Converts employee roles and lifecycle events into a system-by-system provisioning or deprovisioning checklist with approvals, dependencies, and audit evidence fields. Use for joiner, mover, leaver, role-change, access-request, and identity-control preparation.

  • Audit evidence pack

    Organizes audit requests into evidence tests, evaluates supplied documents for coverage and period, and produces a traceable evidence tracker with control narratives and gaps. Use for SOC, ISO, internal control, customer audit, certification, and audit-readiness preparation.

  • Backup and recovery verification

    Checks backup coverage, retention, failures, and recovery-test evidence against system criticality and recovery objectives, then produces a verification report and remediation list. Use for backup audits, disaster-recovery readiness, RTO/RPO reviews, resilience checks, and recurring IT control evidence.

  • Change release record

    Turns a proposed production change into a structured risk, test, approval, rollback, and verification record with traceable evidence. Use for change management, release readiness, deployment review, CAB preparation, rollback planning, and audit documentation.