Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Access Review Campaign Workbook

Holds the campaign data, reviewer decisions and progress tracking for organisations running reviews without an identity governance tool.

Available soon

Format
Excel
Size
232 KB
Length
14 sheets
Version
1.0
Updated

What's inside

  • Instructions
  • Campaign
  • Entries
  • HR Leavers
  • Typed Totals
  • Reviewer Progress
  • System Summary
  • Removals Export
  • Lists
  • Definitions
  • Framework References

Preview

The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.

Instructions

How to use this workbook

StepWhat to do
1On the Campaign sheet, enter the campaign ID, the extract date, the decision deadline and the close date, and set the As-at date. The EXAMPLE uses 2026-09-30; replace it with today's date, or type =TODAY() to keep it current. Flags and progress are measured against it. The yellow settings below (dormant days, list size, removal windows) come from the Access Review Methodology; change them there first.
2List the systems in this campaign in the table on the Campaign sheet, from the Access Review Scope & System Inventory: owner, scope, how access is extracted and the date the extract was taken. The review frequency is calculated from the scope (privileged and administrator access, all systems: every 3 months; systems supporting a critical service (or a critical or important function, DORA; or cardholder data, PCI DSS): every 6 months; all other in-scope systems: every 12 months; AR-02).
3Take each system's extract on its stated date (AR-03) and paste it into the Entries sheet as values, one row per account and permission. The first columns are the ones reviewers see (Entry ID, Person, Job title and department, Employment status, Account, Account type, Permissions, Last sign-in); then choose the System ID. For a generic, service or third-party account, Person is its named owner. Where the account matches nobody, Person reads "No match in HR" and the row is flagged as an orphan account.
4Paste HR's list of people who have left since the last campaign into the HR Leavers sheet. Any entry whose person is on it is flagged as a leaver. Match on the name exactly as the extract gives it, or add an employee number to both sheets and match on that.
5Assign a reviewer to every entry (who reviews what is in the notes below). Nobody may review their own access or the access of anyone who reviews theirs (AR-04): the Self-review column shows where that has happened. Send each reviewer their rows using the Reviewer Instruction Pack & Campaign Communications.
6Record each decision (Keep, Modify, Revoke, Cannot decide), a reason for anything other than Keep, and the date it was made. For privileged, generic and service accounts, and every entry on a privileged system, information security records its second review (AR-06). Where a reviewer finds two duties one person should not hold, enter the conflict ID from the P02 Segregation of Duties Conflict Matrix.
7Watch the Reviewer Progress sheet during the campaign. After the deadline, chase every "No decision" row: nothing is kept by default (AR-05). Before closing, check every reviewer for the rubber-stamp signals (AR-09) and clear every Entry check that does not say OK. The System Summary sheet shows when the campaign is ready to close.
8Copy the Removals Export sheet and paste it as values into the Access Review Findings & Revocation Tracker. Each Revoke and Modify is tracked there to removal and confirmation against a fresh extract (AR-07); leavers, dormant and orphan accounts and conflicts are raised as findings (AR-08).
9Keep this workbook, the extracts and the tracker in the campaign's evidence file (AR-10; the Access Review Evidence & Audit File Checklist), and use the System Summary figures in the Access Review Outcome Report Template. Delete the EXAMPLE rows on every sheet before you start your own campaign.

Legend

Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.

EXAMPLERows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval.

Decisions (AR-05): Keep — access is needed and the permissions are right. Modify — access is needed but some permissions are not: remove the excess. Revoke — access is not needed: remove it. Cannot decide — the reviewer does not know the person or the permission: it goes to the system owner within [[2]] working days, never to Keep by default.

Who reviews what: Line manager — does this person still need access to this system for their current job? System owner — are these the right permissions for that job, and is each privileged or generic account justified? Information security — samples decisions for quality, and reviews every privileged account a second time.

Rubber-stamp signals (AR-09): (1) a reviewer keeps 100% of a large list (more than [[25]] entries) in one sitting; (2) decisions made faster than [[5]] seconds each on average; (3) leavers or dormant accounts (no sign-in for [[90]] days) marked Keep; (4) privileged or generic accounts marked Keep without a named owner. The Reviewer Progress sheet tests each one; the thresholds are the yellow settings on the Campaign sheet.

EXAMPLE: a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders. Campaign UAR-2026-Q3: extract 2026-09-01, decisions due 2026-09-15, closed 2026-09-29; as at 2026-09-30.

Sample plus totals. A real campaign puts every entry on the Entries sheet. To keep the EXAMPLE readable, only the two privileged systems are there in full — all 14 entries for SYS-03 and all 9 for SYS-04. The other three systems (SYS-01, SYS-02, SYS-05, 472 entries) are entered as counts on the Typed Totals sheet. The System Summary sheet adds the two, so it shows the whole campaign: 495 entries, 47 Revoke, 22 Modify and 36 leaver, dormant and orphan accounts. You can use the Typed Totals sheet the same way for a system reviewed in another tool, such as a supplier's portal; never enter the same system on both sheets.

Limitations. A spreadsheet cannot prove who made a decision or how long they spent: ask reviewers to return their rows by email or sign them, and record time spent from their own note or the sharing tool's history. The workbook is only as complete as the extract: reconcile each extract's row count with the system before review (AR-03). Dormancy is measured from the extract date; a service account's use has to be checked in the system's own logs, so it is never flagged dormant here.

Tailoring — small organisation: one coordinator can run a campaign in this workbook for a few hundred entries. Review privileged access every 3 months even if nothing else is in scope yet. Where the Head of IT is also the only administrator, a manager outside IT reviews the Head of IT's own access (AR-04).

Tailoring — regulated entity: DORA Delegated Regulation 2024/1774 Art 21(e) expects access rights to be reviewed at least every six months for systems supporting critical or important functions and at least yearly for others, removed without undue delay, and generic accounts limited and traceable to people (Art 21(c)); NIS2 Art 21(2)(i) expects access control policies. PCI DSS 7.2.4 expects user accounts, including third-party accounts, to be reviewed at least every six months, and 8.2.6 expects inactive accounts to be removed or disabled within 90 days: keep the dormant setting at 90 calendar days or less for systems in cardholder data scope.

Tailoring — IT run by a service provider: the provider usually takes the extract and makes the changes. Ask for the extract with last sign-in, check it is complete, and keep review decisions inside your organisation. Enter the provider's own staff as third-party accounts with the manager of that contract as their named owner, and track the provider's removals in the Access Review Findings & Revocation Tracker against your removal windows (PW-02 is the EXAMPLE of a provider slower than the window).

Campaign

Campaign control

The campaign's dates and settings, and the systems it covers. Yellow cells are inputs.

Campaign IDUAR-2026-Q3EXAMPLE. Use one ID per campaign, for example UAR-YYYY-Qn.
Campaign coordinator[[e.g. Information Security Manager]]Runs the campaign; not a reviewer of their own access.
Extract date1 Sep 2026EXAMPLE. The date the extracts were taken (AR-03). A system's own date on the table below overrides it.
Decision deadline15 Sep 2026EXAMPLE. After this date an entry without a decision is flagged (AR-05).
Close date29 Sep 2026EXAMPLE. Removals confirmed, quality checked and evidence filed (AR-07, AR-09, AR-10).
As-at date30 Sep 2026EXAMPLE date. Replace it with today's date, or type =TODAY() to keep it current.
Dormant after (calendar days without sign-in)90Counted back from the extract date. PCI DSS 8.2.6: no more than 90 calendar days in cardholder data scope.
Large list (entries for one reviewer)25A reviewer who keeps 100% of a list longer than this is flagged (AR-09).
Fast decisions (seconds each, on average)5A reviewer whose decisions average less than this is flagged (AR-09).
Cannot decide goes to the system owner within (working days)2Never Keep by default (AR-05).
Removal window: privileged access (working days)1From the decision deadline (AR-07). Used on the Removals Export.
Removal window: other access (working days)5From the decision deadline (AR-07).

Systems in this campaign

ExampleSystem IDSystemSystem ownerScopeReview every (months, calc)Privileged system (calc)How access is extractedExtract dateRows on Entries (calc)Typed entries (calc)Entries reviewed (calc)
EXAMPLESYS-01ERP (hosted; P06 SUP-004)Chief Financial OfficerSystems supporting a critical service (or a critical or important function, DORA; or cardholder data, PCI DSS)6NoSupplier-run user report, requested by ticket1 Sep 20260164164
EXAMPLESYS-02Warehouse management systemHead of LogisticsSystems supporting a critical service (or a critical or important function, DORA; or cardholder data, PCI DSS)6NoAdmin console export1 Sep 20260212212
EXAMPLESYS-03Directory administrator groupsHead of ITPrivileged and administrator access, all systems3YesGroup membership export1 Sep 202614014
EXAMPLESYS-04Online ordering admin consoleChief Operating OfficerPrivileged and administrator access, all systems3YesAdmin console export1 Sep 2026909
EXAMPLESYS-05Shared finance driveChief Financial OfficerAll other in-scope systems12NoPermissions report1 Sep 202609696

Entries

One row per account and permission. Yellow columns are yours; white columns calculate. Every colour sits beside a word.

ExampleEntry IDPersonJob title and departmentEmployment statusAccountAccount typePermissionsLast sign-inDecisionReasonSystem IDReviewer assignedDecided onSoD conflict (P02 conflict ID)Information security second review (AR-06)Days since sign-in (calc)Dormant (calc)Leaver (calc)Should not exist (calc)Self-review (AR-04, calc)Privileged (calc)Removal type (calc)Removal window, working days (calc)Removal no. (calc)Entry check (calc)Notes
EXAMPLES03-01Mark EllisHead of IT, ITActiveadm-mellisPrivilegedDomain Admins20 Aug 2026KeepHead of IT: owns the directory. Reviewed by information security, not by himself (AR-04).SYS-03Ruth Okafor11 Sep 2026Not needed12YesOK
EXAMPLES03-02Jana NovakInfrastructure Engineer, ITActiveadm-jnovakPrivilegedDomain Admins31 Aug 2026KeepSYS-03Mark Ellis8 Sep 2026Agreed1YesOK
EXAMPLES03-03Priya ShahInfrastructure Engineer, ITActiveadm-pshahPrivilegedServer Admins28 Aug 2026KeepSYS-03Mark Ellis8 Sep 2026Agreed4YesOK
EXAMPLES03-04Priya ShahInfrastructure Engineer, ITActiveadm-pshahPrivilegedBackup Operators28 Aug 2026KeepSYS-03Mark Ellis8 Sep 2026Agreed4YesOK
EXAMPLES03-05Dan MorganService Desk Lead, ITActiveadm-dmorganPrivilegedHelpdesk Admins: reset passwords, unlock and create accounts30 Aug 2026ModifyKeep reset and unlock. Creating accounts belongs to the joiner process: remove that delegation.SYS-03Mark Ellis8 Sep 2026Agreed2YesExcess permission11OK
EXAMPLES03-06Li ChenService Desk Analyst, ITActiveadm-lchenPrivilegedHelpdesk Admins: reset passwords, unlock accounts27 Aug 2026KeepSYS-03Mark Ellis8 Sep 2026Agreed5YesOK
EXAMPLES03-07Alex TurnerEngineer, managed IT service provider (P06 SUP-001), ExternalThird partyext-msp-aturnerThird-partyServer Admins25 Aug 2026KeepSYS-03Mark Ellis8 Sep 2026Agreed7YesOK
EXAMPLES03-08Beth OwenEngineer, managed IT service provider (P06 SUP-001), ExternalThird partyext-msp-bowenThird-partyServer Admins18 Aug 2026KeepSYS-03Mark Ellis8 Sep 2026Agreed14YesOK
EXAMPLES03-09Nina FieldAnalyst, security monitoring provider (P06 SUP-006), ExternalThird partyext-soc-nfieldThird-partyEvent Log Readers, all servers31 Aug 2026KeepSYS-03Mark Ellis8 Sep 2026Agreed1YesOK
EXAMPLES03-10Priya ShahNamed owner of the backup job account, ITActivesvc-backupServiceBackup OperatorsKeepRuns the nightly backup jobs; no interactive sign-in.SYS-03Mark Ellis8 Sep 2026AgreedNeverYesOK
EXAMPLES03-11Mark EllisNamed owner of the break-glass account, ITActivebg-emergencyGenericDomain Admins15 Jun 2026KeepBreak-glass account; password sealed in the safe; last used for the June test.SYS-03Ruth Okafor11 Sep 2026Not needed78YesOK
EXAMPLES03-12Kieran WalshNetwork Engineer, ITLeaveradm-kwalshPrivilegedDomain Admins19 Jun 2026RevokeLeft on 2026-06-30 (HR leavers list). His everyday account was disabled; this administrator account was missed.SYS-03Mark Ellis8 Sep 2026Agreed74LeaverLeaverYesLeaver12OK
EXAMPLES03-13No match in HRNo match in HRadm-migrationGenericDomain Admins3 Nov 2025RevokeNo owner found. Created for the 2025 server migration and never removed.SYS-03Mark Ellis8 Sep 2026Agreed302DormantOrphanYesOrphan13OK
EXAMPLES03-14Ravi PatelApplication Support Analyst, ApplicationsActiveadm-rpatelPrivilegedServer Admins12 Aug 2026RevokeMoved from infrastructure to application support in May; no longer administers servers.SYS-03Mark Ellis8 Sep 2026Agreed20YesNo longer needed14OK
EXAMPLES04-01Elena LopezE-commerce Manager, Online SalesActiveelena.lopezPrivilegedStore administrator31 Aug 2026KeepSYS-04Helen Carter10 Sep 2026Agreed1YesOK
EXAMPLES04-02Helen CarterChief Operating Officer, OperationsActivehelen.carterPrivilegedStore administrator10 Jul 2026KeepSystem owner's own account. Reviewed by information security, not by herself (AR-04).SYS-04Ruth Okafor11 Sep 2026Not needed53YesOK
EXAMPLES04-03Omar HaddadOnline Merchandiser, Online SalesActiveomar.haddadPersonalCatalogue and pricing editor30 Aug 2026KeepSYS-04Helen Carter10 Sep 2026Agreed2YesOK
EXAMPLES04-04Sara WhyteOnline Merchandiser, Online SalesActivesara.whytePersonalCatalogue and pricing editor28 Aug 2026KeepSYS-04Helen Carter10 Sep 2026Agreed4YesOK
EXAMPLES04-05Grace KimCustomer Service Team Leader, Customer ServiceActivegrace.kimPersonalOrders and refunds31 Aug 2026KeepSYS-04Helen Carter10 Sep 2026Agreed1YesOK
EXAMPLES04-06Tom ReidCustomer Service Advisor, Customer ServiceActivetom.reidPersonalOrders: view and amend29 Aug 2026KeepSYS-04Helen Carter10 Sep 2026Agreed3YesOK
EXAMPLES04-07Ben AdamsCustomer Service Advisor, Customer ServiceActiveben.adamsPersonalOrders: view and amend26 Aug 2026KeepSYS-04Helen Carter10 Sep 2026Agreed6YesOK
EXAMPLES04-08Marta SilvaMarketing Executive, MarketingActivemarta.silvaPersonalPromotions editor20 Apr 2026RevokeNo sign-in since April; promotions are now set up by the online merchandisers.SYS-04Helen Carter10 Sep 2026Agreed134DormantDormantYesDormant15OK
EXAMPLES04-09No match in HRNo match in HRj.harperPrivilegedStore administrator14 Jan 2026RevokeConsole account whose email matches no current or former employee. Nobody claims it.SYS-04Helen Carter10 Sep 2026Agreed230DormantOrphanYesOrphan16OK

HR Leavers

HR's list of people who have left since the last campaign. An entry whose person is here, with a leaving date on or before the As-at date, is flagged Leaver.

ExampleName (as in the extracts)DepartmentLeaving dateEntries still held (calc)Of those, not revoked (calc)Notes
EXAMPLEKieran WalshIT30 Jun 202610EXAMPLE: administrator account still active in SYS-03 (entry S03-12).
EXAMPLEChloe DunnOnline Sales17 Jul 202600EXAMPLE: left before the campaign; no access found in the detailed systems.
EXAMPLEPeter LangFinance7 Aug 202600EXAMPLE: left before the campaign; no access found in the detailed systems.

Typed Totals

Counts for a system whose entries are not on the Entries sheet (see Instructions: sample plus totals). The System Summary sheet adds them to the entries.

ExampleSystem IDEntries reviewedKeepModifyRevokeCannot decideLeaversDormantOrphanSoD conflictsWhere the entry-level detail is keptCheck (calc)
EXAMPLESYS-01164139111223611EXAMPLE: the ERP provider's user report (P06 SUP-004), returned with decisions and filed with the campaign evidence. The SoD conflict: the accounts payable supervisor could create or change suppliers and their bank details and approve payments (P02 SOD-FI-01, rated High); separated by a Modify; no exception.OK
EXAMPLESYS-0221218861807900EXAMPLE: the admin console export, one file per warehouse, with decisions, filed with the campaign evidence.OK
EXAMPLESYS-05968041202400EXAMPLE: the permissions report, with decisions, filed with the campaign evidence.OK

Reviewer Progress

One row per reviewer, named exactly as in the Reviewer assigned column. Counts come from the Entries sheet. The quality signals are AR-09's rubber-stamp checks; numbers match the Instructions sheet.

ExampleReviewerRole and what they reviewAssigned (calc)Decided (calc)Keep (calc)Modify (calc)Revoke (calc)Cannot decide (calc)Decided (%, calc)Keep (%, calc)Time spent reviewing (minutes)Seconds per decision (calc)Leavers or dormant kept (calc)Privileged or generic kept without an owner (calc)Self-review entries (calc)Quality signals (calc)Notes
EXAMPLEMark EllisHead of IT — system owner, SYS-0312128130100%67%35175000None
EXAMPLEHelen CarterChief Operating Officer — system owner, SYS-04886020100%75%20150000None
EXAMPLERuth OkaforHead of Information Security — second reviewer; reviews the two system owners' own access333000100%100%10200000None

System Summary

System summary

Every figure adds the rows on the Entries sheet to the counts on the Typed Totals sheet, so it covers the whole campaign. Use it in the Access Review Outcome Report Template.

Results by system

System IDSystemRows on EntriesTyped entriesEntries reviewedKeepModifyRevokeCannot decideNo decision yetLeaversDormantOrphanSoD conflictsRemovals to trackCheck
SYS-01ERP (hosted; P06 SUP-004)0164164139111220361123OK
SYS-02Warehouse management system021221218861800790024OK
SYS-03Directory administrator groups1401410130010104OK
SYS-04Online ordering admin console9097020001102OK
SYS-05Shared finance drive096968041200240016OK
All systems2347249542422472013203169

EXAMPLE: SYS-03 and SYS-04 come from the Entries sheet, the other systems from the Typed Totals sheet. Leavers, dormant and orphan accounts are within Revoke.

Campaign at a glance

MeasureResultWhat it means
Entries reviewed495495 in the EXAMPLE.
Revoke and Modify decisions to track69Paste the Removals Export into the Access Review Findings & Revocation Tracker (AR-07); its ARM-02 measures them.
ARM-03 Access that should not have existed36Leaver, dormant and orphan accounts found in the campaign. Target: falling campaign on campaign.
Segregation-of-duties conflicts found1Handle each with the P02 Segregation of Duties Conflict Matrix and, where accepted, an exception (AR-08).
Cannot decide, passed to the system owner2Decided by the system owner within 2 working days; never Keep by default.
Entries with no decision yet0Detailed entries only. After the deadline each is chased; none is kept by default (AR-05).
Entries with a check to resolve0Any row on the Entries sheet whose Entry check does not say OK.
Reviewers with a quality signal0Rubber-stamp signals on the Reviewer Progress sheet (AR-09).
Ready to close?Ready to closeEvery entry decided, every check OK and no reviewer flagged. Removals are confirmed in the tracker before the close date.

Campaign sign-off (AR-09, AR-10)

ItemEntry
Quality check done by (name, role) and date[[Name, role, YYYY-MM-DD]]
Rubber-stamp signals found and what was done[[e.g. none; or reviewer re-did their list on YYYY-MM-DD]]
Campaign closed by (name, role) and date[[Name, role, YYYY-MM-DD]]

Removals Export

Calculated: every Revoke and Modify on the Entries sheet, in order. Copy columns B to L and paste them as values into the Access Review Findings & Revocation Tracker's Removals sheet, from its Removal ID column.

Entry row (calc)Removal IDCampaignEntry IDSystem IDAccountPersonDecisionTypePrivilegedDecided onDecision deadlineReason
5UAR-2026-Q3-R01UAR-2026-Q3S03-05SYS-03adm-dmorganDan MorganModifyExcess permissionYes8 Sep 202615 Sep 2026Keep reset and unlock. Creating accounts belongs to the joiner process: remove that delegation.
12UAR-2026-Q3-R02UAR-2026-Q3S03-12SYS-03adm-kwalshKieran WalshRevokeLeaverYes8 Sep 202615 Sep 2026Left on 2026-06-30 (HR leavers list). His everyday account was disabled; this administrator account was missed.
13UAR-2026-Q3-R03UAR-2026-Q3S03-13SYS-03adm-migrationNo match in HRRevokeOrphanYes8 Sep 202615 Sep 2026No owner found. Created for the 2025 server migration and never removed.
14UAR-2026-Q3-R04UAR-2026-Q3S03-14SYS-03adm-rpatelRavi PatelRevokeNo longer neededYes8 Sep 202615 Sep 2026Moved from infrastructure to application support in May; no longer administers servers.
22UAR-2026-Q3-R05UAR-2026-Q3S04-08SYS-04marta.silvaMarta SilvaRevokeDormantYes10 Sep 202615 Sep 2026No sign-in since April; promotions are now set up by the online merchandisers.
23UAR-2026-Q3-R06UAR-2026-Q3S04-09SYS-04j.harperNo match in HRRevokeOrphanYes10 Sep 202615 Sep 2026Console account whose email matches no current or former employee. Nobody claims it.

Lists

DecisionAccountTypeEmploymentStatusSecondReviewScopeScopeMonthsRemovalType
KeepPersonalActiveAgreedPrivileged and administrator access, all systems3Leaver
ModifyPrivilegedLeaverChallengedSystems supporting a critical service (or a critical or important function, DORA; or cardholder data, PCI DSS)6Dormant
RevokeGenericLong-term leaveNot neededAll other in-scope systems12Orphan
Cannot decideServiceContractorExcess permission
Third-partyThird partySoD conflict
No match in HRNo longer needed

Definitions

Definitions

TermMeaning in this workbook
CampaignOne round of access review across the systems in scope, from the extract to sign-off, with its own ID (for example UAR-2026-Q3).
EntryOne account holding one permission (a role, group or set of rights) in one system. A person with three roles in a system has three entries.
ExtractThe list of who has access, taken from the system on a stated date (AR-03): the extract must be complete and taken on a stated date; the reviewer must see names, roles, permissions and last sign-in.
Decision — KeepAccess is needed and the permissions are right.
Decision — ModifyAccess is needed but some permissions are not: remove the excess.
Decision — RevokeAccess is not needed: remove it.
Decision — Cannot decideThe reviewer does not know the person or the permission: it goes to the system owner within [[2]] working days, never to Keep by default.
Account type — PersonalBelongs to one named employee or contractor for their own work. Owner: the person; their line manager answers for the need.
Account type — PrivilegedCan change the system, its settings, its users or its security: administrator groups, super-user roles, database owners. Owner: a named person, even where the account is separate from their personal account (AR-06).
Account type — GenericUsed by more than one person, or by a role rather than a person: a warehouse terminal login, a shared mailbox with sign-in, a training account. Owner: a named manager who answers for every use of it (AR-06).
Account type — ServiceUsed by software, not a person: an interface between two systems, a scheduled job, a backup agent. Owner: a named technical owner who knows what uses it (AR-06).
Account type — Third-partyHeld by someone outside the organisation: a supplier's support staff, a contractor, an auditor, a customer on an admin console. Owner: the manager who manages that supplier or contract.
Dormant accountAn account with no sign-in for more than the dormant setting (90 calendar days by default) before the extract date, or never signed in. Service accounts are not flagged: check their use in the system's logs.
LeaverA person on the HR Leavers sheet with a leaving date on or before the As-at date. Any access they still hold should not exist.
Orphan accountAn account nobody can be matched to: no current person and no named owner. Its Person reads "No match in HR".
Employment statusFrom HR on the extract date: Active, Leaver, Long-term leave, Contractor, Third party, No match in HR. Leaver also flags the entry, as does the HR Leavers sheet.
Should not existLeaver, orphan or dormant, in that order when more than one applies. Together they are ARM-03, access that should not have existed; each is raised as a finding (AR-08).
Self-reviewNobody may review their own access or the access of anyone who reviews theirs. Own access: the reviewer is the person on the entry. Reviews their reviewer: the person on the entry reviews some of the reviewer's own entries.
PrivilegedAn entry on a system whose scope is "Privileged and administrator access, all systems", or an account of type Privileged. Removal window 1 working day; other access 5 working days, counted from the campaign's decision deadline (AR-07).
Second reviewInformation security: samples decisions for quality, and reviews every privileged account a second time. Agreed, Challenged, or Not needed when information security was the reviewer.
Removal typeWhat a Revoke or Modify removes: Leaver, Dormant, Orphan, Excess permission, SoD conflict, No longer needed. Set by the flags and the SoD conflict column; the tracker uses it.
SoD conflictTwo duties one person should not hold together, from the P02 Segregation of Duties Conflict Matrix. Enter its conflict ID.
Rubber-stamp signalsA reviewer keeps 100% of a large list (more than [[25]] entries) in one sitting; Decisions made faster than [[5]] seconds each on average; Leavers or dormant accounts (no sign-in for [[90]] days) marked Keep; Privileged or generic accounts marked Keep without a named owner. Checked before the campaign is closed (AR-09).
Typed totalsCounts entered for a system whose entries are kept outside this workbook. Used in the EXAMPLE for SYS-01, SYS-02, SYS-05.
As-at dateThe date flags and progress are measured against. Set on the Campaign sheet.
EXAMPLE rowA worked example: a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders, campaign UAR-2026-Q3, as at 2026-09-30. People are fictional. Delete before use.
AR-nn, ARM-nn, SYS-nn, PW-nnRule, measure, system and process weakness numbers in the Access Review Methodology and the pack's EXAMPLE.
(calc)A column or cell the workbook calculates. Do not type or paste over it.

Framework References

Framework references

These references indicate relevance only and do not reproduce the text of any standard.

FrameworkReferenceSupported by
ISO/IEC 27001:2022Annex A 5.18 — Access rightsEntries, decisions and reasons: access rights reviewed and changed at planned intervals
ISO/IEC 27001:2022Annex A 8.2 — Privileged access rightsPrivileged system and account flags, information security second review, 1-working-day removal window
NIST CSF 2.0PR.AA-05 — “Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties”Entries with decisions; SoD conflict column; Removals Export for least privilege
DORA — Delegated Regulation (EU) 2024/1774Article 21(c) — user accountability: generic and shared accounts limited, and users identifiable for their actionsGeneric and service accounts need a named owner; orphan accounts flagged
DORA — Delegated Regulation (EU) 2024/1774Article 21(e) — account management: roles for granting, reviewing and revoking access; privileged access on a need-to-use basis; removal without undue delay; review at least every six months for systems supporting critical or important functions and at least yearly for othersReview frequency by scope on the Campaign sheet; removal windows; privileged access reviewed twice
PCI DSS v4.0.1Requirement 7.2.4 — user accounts and their access privileges, including third-party accounts, reviewed at least every six monthsEvery account reviewed, including third-party accounts, with review frequency by scope
PCI DSS v4.0.1Requirement 8.2.6 — inactive user accounts removed or disabled within 90 daysDormant flag: no sign-in for 90 calendar days

Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774; PCI DSS v4.0.1