Access Review Campaign Workbook
Holds the campaign data, reviewer decisions and progress tracking for organisations running reviews without an identity governance tool.
Available soon
- Format
- Excel
- Size
- 232 KB
- Length
- 14 sheets
- Version
- 1.0
- Updated
What's inside
- Instructions
- Campaign
- Entries
- HR Leavers
- Typed Totals
- Reviewer Progress
- System Summary
- Removals Export
- Lists
- Definitions
- Framework References
Preview
The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.
Instructions
How to use this workbook
| Step | What to do |
|---|---|
| 1 | On the Campaign sheet, enter the campaign ID, the extract date, the decision deadline and the close date, and set the As-at date. The EXAMPLE uses 2026-09-30; replace it with today's date, or type =TODAY() to keep it current. Flags and progress are measured against it. The yellow settings below (dormant days, list size, removal windows) come from the Access Review Methodology; change them there first. |
| 2 | List the systems in this campaign in the table on the Campaign sheet, from the Access Review Scope & System Inventory: owner, scope, how access is extracted and the date the extract was taken. The review frequency is calculated from the scope (privileged and administrator access, all systems: every 3 months; systems supporting a critical service (or a critical or important function, DORA; or cardholder data, PCI DSS): every 6 months; all other in-scope systems: every 12 months; AR-02). |
| 3 | Take each system's extract on its stated date (AR-03) and paste it into the Entries sheet as values, one row per account and permission. The first columns are the ones reviewers see (Entry ID, Person, Job title and department, Employment status, Account, Account type, Permissions, Last sign-in); then choose the System ID. For a generic, service or third-party account, Person is its named owner. Where the account matches nobody, Person reads "No match in HR" and the row is flagged as an orphan account. |
| 4 | Paste HR's list of people who have left since the last campaign into the HR Leavers sheet. Any entry whose person is on it is flagged as a leaver. Match on the name exactly as the extract gives it, or add an employee number to both sheets and match on that. |
| 5 | Assign a reviewer to every entry (who reviews what is in the notes below). Nobody may review their own access or the access of anyone who reviews theirs (AR-04): the Self-review column shows where that has happened. Send each reviewer their rows using the Reviewer Instruction Pack & Campaign Communications. |
| 6 | Record each decision (Keep, Modify, Revoke, Cannot decide), a reason for anything other than Keep, and the date it was made. For privileged, generic and service accounts, and every entry on a privileged system, information security records its second review (AR-06). Where a reviewer finds two duties one person should not hold, enter the conflict ID from the P02 Segregation of Duties Conflict Matrix. |
| 7 | Watch the Reviewer Progress sheet during the campaign. After the deadline, chase every "No decision" row: nothing is kept by default (AR-05). Before closing, check every reviewer for the rubber-stamp signals (AR-09) and clear every Entry check that does not say OK. The System Summary sheet shows when the campaign is ready to close. |
| 8 | Copy the Removals Export sheet and paste it as values into the Access Review Findings & Revocation Tracker. Each Revoke and Modify is tracked there to removal and confirmation against a fresh extract (AR-07); leavers, dormant and orphan accounts and conflicts are raised as findings (AR-08). |
| 9 | Keep this workbook, the extracts and the tracker in the campaign's evidence file (AR-10; the Access Review Evidence & Audit File Checklist), and use the System Summary figures in the Access Review Outcome Report Template. Delete the EXAMPLE rows on every sheet before you start your own campaign. |
Legend
Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.
| EXAMPLE | Rows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval. |
Decisions (AR-05): Keep — access is needed and the permissions are right. Modify — access is needed but some permissions are not: remove the excess. Revoke — access is not needed: remove it. Cannot decide — the reviewer does not know the person or the permission: it goes to the system owner within [[2]] working days, never to Keep by default.
Who reviews what: Line manager — does this person still need access to this system for their current job? System owner — are these the right permissions for that job, and is each privileged or generic account justified? Information security — samples decisions for quality, and reviews every privileged account a second time.
Rubber-stamp signals (AR-09): (1) a reviewer keeps 100% of a large list (more than [[25]] entries) in one sitting; (2) decisions made faster than [[5]] seconds each on average; (3) leavers or dormant accounts (no sign-in for [[90]] days) marked Keep; (4) privileged or generic accounts marked Keep without a named owner. The Reviewer Progress sheet tests each one; the thresholds are the yellow settings on the Campaign sheet.
EXAMPLE: a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders. Campaign UAR-2026-Q3: extract 2026-09-01, decisions due 2026-09-15, closed 2026-09-29; as at 2026-09-30.
Sample plus totals. A real campaign puts every entry on the Entries sheet. To keep the EXAMPLE readable, only the two privileged systems are there in full — all 14 entries for SYS-03 and all 9 for SYS-04. The other three systems (SYS-01, SYS-02, SYS-05, 472 entries) are entered as counts on the Typed Totals sheet. The System Summary sheet adds the two, so it shows the whole campaign: 495 entries, 47 Revoke, 22 Modify and 36 leaver, dormant and orphan accounts. You can use the Typed Totals sheet the same way for a system reviewed in another tool, such as a supplier's portal; never enter the same system on both sheets.
Limitations. A spreadsheet cannot prove who made a decision or how long they spent: ask reviewers to return their rows by email or sign them, and record time spent from their own note or the sharing tool's history. The workbook is only as complete as the extract: reconcile each extract's row count with the system before review (AR-03). Dormancy is measured from the extract date; a service account's use has to be checked in the system's own logs, so it is never flagged dormant here.
Tailoring — small organisation: one coordinator can run a campaign in this workbook for a few hundred entries. Review privileged access every 3 months even if nothing else is in scope yet. Where the Head of IT is also the only administrator, a manager outside IT reviews the Head of IT's own access (AR-04).
Tailoring — regulated entity: DORA Delegated Regulation 2024/1774 Art 21(e) expects access rights to be reviewed at least every six months for systems supporting critical or important functions and at least yearly for others, removed without undue delay, and generic accounts limited and traceable to people (Art 21(c)); NIS2 Art 21(2)(i) expects access control policies. PCI DSS 7.2.4 expects user accounts, including third-party accounts, to be reviewed at least every six months, and 8.2.6 expects inactive accounts to be removed or disabled within 90 days: keep the dormant setting at 90 calendar days or less for systems in cardholder data scope.
Tailoring — IT run by a service provider: the provider usually takes the extract and makes the changes. Ask for the extract with last sign-in, check it is complete, and keep review decisions inside your organisation. Enter the provider's own staff as third-party accounts with the manager of that contract as their named owner, and track the provider's removals in the Access Review Findings & Revocation Tracker against your removal windows (PW-02 is the EXAMPLE of a provider slower than the window).
Campaign
Campaign control
The campaign's dates and settings, and the systems it covers. Yellow cells are inputs.
| Campaign ID | UAR-2026-Q3 | EXAMPLE. Use one ID per campaign, for example UAR-YYYY-Qn. | |||||
| Campaign coordinator | [[e.g. Information Security Manager]] | Runs the campaign; not a reviewer of their own access. | |||||
| Extract date | 1 Sep 2026 | EXAMPLE. The date the extracts were taken (AR-03). A system's own date on the table below overrides it. | |||||
| Decision deadline | 15 Sep 2026 | EXAMPLE. After this date an entry without a decision is flagged (AR-05). | |||||
| Close date | 29 Sep 2026 | EXAMPLE. Removals confirmed, quality checked and evidence filed (AR-07, AR-09, AR-10). | |||||
| As-at date | 30 Sep 2026 | EXAMPLE date. Replace it with today's date, or type =TODAY() to keep it current. | |||||
| Dormant after (calendar days without sign-in) | 90 | Counted back from the extract date. PCI DSS 8.2.6: no more than 90 calendar days in cardholder data scope. | |||||
| Large list (entries for one reviewer) | 25 | A reviewer who keeps 100% of a list longer than this is flagged (AR-09). | |||||
| Fast decisions (seconds each, on average) | 5 | A reviewer whose decisions average less than this is flagged (AR-09). | |||||
| Cannot decide goes to the system owner within (working days) | 2 | Never Keep by default (AR-05). | |||||
| Removal window: privileged access (working days) | 1 | From the decision deadline (AR-07). Used on the Removals Export. | |||||
| Removal window: other access (working days) | 5 | From the decision deadline (AR-07). | |||||
Systems in this campaign
| Example | System ID | System | System owner | Scope | Review every (months, calc) | Privileged system (calc) | How access is extracted | Extract date | Rows on Entries (calc) | Typed entries (calc) | Entries reviewed (calc) |
|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | SYS-01 | ERP (hosted; P06 SUP-004) | Chief Financial Officer | Systems supporting a critical service (or a critical or important function, DORA; or cardholder data, PCI DSS) | 6 | No | Supplier-run user report, requested by ticket | 1 Sep 2026 | 0 | 164 | 164 |
| EXAMPLE | SYS-02 | Warehouse management system | Head of Logistics | Systems supporting a critical service (or a critical or important function, DORA; or cardholder data, PCI DSS) | 6 | No | Admin console export | 1 Sep 2026 | 0 | 212 | 212 |
| EXAMPLE | SYS-03 | Directory administrator groups | Head of IT | Privileged and administrator access, all systems | 3 | Yes | Group membership export | 1 Sep 2026 | 14 | 0 | 14 |
| EXAMPLE | SYS-04 | Online ordering admin console | Chief Operating Officer | Privileged and administrator access, all systems | 3 | Yes | Admin console export | 1 Sep 2026 | 9 | 0 | 9 |
| EXAMPLE | SYS-05 | Shared finance drive | Chief Financial Officer | All other in-scope systems | 12 | No | Permissions report | 1 Sep 2026 | 0 | 96 | 96 |
Entries
One row per account and permission. Yellow columns are yours; white columns calculate. Every colour sits beside a word.
| Example | Entry ID | Person | Job title and department | Employment status | Account | Account type | Permissions | Last sign-in | Decision | Reason | System ID | Reviewer assigned | Decided on | SoD conflict (P02 conflict ID) | Information security second review (AR-06) | Days since sign-in (calc) | Dormant (calc) | Leaver (calc) | Should not exist (calc) | Self-review (AR-04, calc) | Privileged (calc) | Removal type (calc) | Removal window, working days (calc) | Removal no. (calc) | Entry check (calc) | Notes |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | S03-01 | Mark Ellis | Head of IT, IT | Active | adm-mellis | Privileged | Domain Admins | 20 Aug 2026 | Keep | Head of IT: owns the directory. Reviewed by information security, not by himself (AR-04). | SYS-03 | Ruth Okafor | 11 Sep 2026 | Not needed | 12 | Yes | OK | |||||||||
| EXAMPLE | S03-02 | Jana Novak | Infrastructure Engineer, IT | Active | adm-jnovak | Privileged | Domain Admins | 31 Aug 2026 | Keep | SYS-03 | Mark Ellis | 8 Sep 2026 | Agreed | 1 | Yes | OK | ||||||||||
| EXAMPLE | S03-03 | Priya Shah | Infrastructure Engineer, IT | Active | adm-pshah | Privileged | Server Admins | 28 Aug 2026 | Keep | SYS-03 | Mark Ellis | 8 Sep 2026 | Agreed | 4 | Yes | OK | ||||||||||
| EXAMPLE | S03-04 | Priya Shah | Infrastructure Engineer, IT | Active | adm-pshah | Privileged | Backup Operators | 28 Aug 2026 | Keep | SYS-03 | Mark Ellis | 8 Sep 2026 | Agreed | 4 | Yes | OK | ||||||||||
| EXAMPLE | S03-05 | Dan Morgan | Service Desk Lead, IT | Active | adm-dmorgan | Privileged | Helpdesk Admins: reset passwords, unlock and create accounts | 30 Aug 2026 | Modify | Keep reset and unlock. Creating accounts belongs to the joiner process: remove that delegation. | SYS-03 | Mark Ellis | 8 Sep 2026 | Agreed | 2 | Yes | Excess permission | 1 | 1 | OK | ||||||
| EXAMPLE | S03-06 | Li Chen | Service Desk Analyst, IT | Active | adm-lchen | Privileged | Helpdesk Admins: reset passwords, unlock accounts | 27 Aug 2026 | Keep | SYS-03 | Mark Ellis | 8 Sep 2026 | Agreed | 5 | Yes | OK | ||||||||||
| EXAMPLE | S03-07 | Alex Turner | Engineer, managed IT service provider (P06 SUP-001), External | Third party | ext-msp-aturner | Third-party | Server Admins | 25 Aug 2026 | Keep | SYS-03 | Mark Ellis | 8 Sep 2026 | Agreed | 7 | Yes | OK | ||||||||||
| EXAMPLE | S03-08 | Beth Owen | Engineer, managed IT service provider (P06 SUP-001), External | Third party | ext-msp-bowen | Third-party | Server Admins | 18 Aug 2026 | Keep | SYS-03 | Mark Ellis | 8 Sep 2026 | Agreed | 14 | Yes | OK | ||||||||||
| EXAMPLE | S03-09 | Nina Field | Analyst, security monitoring provider (P06 SUP-006), External | Third party | ext-soc-nfield | Third-party | Event Log Readers, all servers | 31 Aug 2026 | Keep | SYS-03 | Mark Ellis | 8 Sep 2026 | Agreed | 1 | Yes | OK | ||||||||||
| EXAMPLE | S03-10 | Priya Shah | Named owner of the backup job account, IT | Active | svc-backup | Service | Backup Operators | Keep | Runs the nightly backup jobs; no interactive sign-in. | SYS-03 | Mark Ellis | 8 Sep 2026 | Agreed | Never | Yes | OK | ||||||||||
| EXAMPLE | S03-11 | Mark Ellis | Named owner of the break-glass account, IT | Active | bg-emergency | Generic | Domain Admins | 15 Jun 2026 | Keep | Break-glass account; password sealed in the safe; last used for the June test. | SYS-03 | Ruth Okafor | 11 Sep 2026 | Not needed | 78 | Yes | OK | |||||||||
| EXAMPLE | S03-12 | Kieran Walsh | Network Engineer, IT | Leaver | adm-kwalsh | Privileged | Domain Admins | 19 Jun 2026 | Revoke | Left on 2026-06-30 (HR leavers list). His everyday account was disabled; this administrator account was missed. | SYS-03 | Mark Ellis | 8 Sep 2026 | Agreed | 74 | Leaver | Leaver | Yes | Leaver | 1 | 2 | OK | ||||
| EXAMPLE | S03-13 | No match in HR | No match in HR | adm-migration | Generic | Domain Admins | 3 Nov 2025 | Revoke | No owner found. Created for the 2025 server migration and never removed. | SYS-03 | Mark Ellis | 8 Sep 2026 | Agreed | 302 | Dormant | Orphan | Yes | Orphan | 1 | 3 | OK | |||||
| EXAMPLE | S03-14 | Ravi Patel | Application Support Analyst, Applications | Active | adm-rpatel | Privileged | Server Admins | 12 Aug 2026 | Revoke | Moved from infrastructure to application support in May; no longer administers servers. | SYS-03 | Mark Ellis | 8 Sep 2026 | Agreed | 20 | Yes | No longer needed | 1 | 4 | OK | ||||||
| EXAMPLE | S04-01 | Elena Lopez | E-commerce Manager, Online Sales | Active | elena.lopez | Privileged | Store administrator | 31 Aug 2026 | Keep | SYS-04 | Helen Carter | 10 Sep 2026 | Agreed | 1 | Yes | OK | ||||||||||
| EXAMPLE | S04-02 | Helen Carter | Chief Operating Officer, Operations | Active | helen.carter | Privileged | Store administrator | 10 Jul 2026 | Keep | System owner's own account. Reviewed by information security, not by herself (AR-04). | SYS-04 | Ruth Okafor | 11 Sep 2026 | Not needed | 53 | Yes | OK | |||||||||
| EXAMPLE | S04-03 | Omar Haddad | Online Merchandiser, Online Sales | Active | omar.haddad | Personal | Catalogue and pricing editor | 30 Aug 2026 | Keep | SYS-04 | Helen Carter | 10 Sep 2026 | Agreed | 2 | Yes | OK | ||||||||||
| EXAMPLE | S04-04 | Sara Whyte | Online Merchandiser, Online Sales | Active | sara.whyte | Personal | Catalogue and pricing editor | 28 Aug 2026 | Keep | SYS-04 | Helen Carter | 10 Sep 2026 | Agreed | 4 | Yes | OK | ||||||||||
| EXAMPLE | S04-05 | Grace Kim | Customer Service Team Leader, Customer Service | Active | grace.kim | Personal | Orders and refunds | 31 Aug 2026 | Keep | SYS-04 | Helen Carter | 10 Sep 2026 | Agreed | 1 | Yes | OK | ||||||||||
| EXAMPLE | S04-06 | Tom Reid | Customer Service Advisor, Customer Service | Active | tom.reid | Personal | Orders: view and amend | 29 Aug 2026 | Keep | SYS-04 | Helen Carter | 10 Sep 2026 | Agreed | 3 | Yes | OK | ||||||||||
| EXAMPLE | S04-07 | Ben Adams | Customer Service Advisor, Customer Service | Active | ben.adams | Personal | Orders: view and amend | 26 Aug 2026 | Keep | SYS-04 | Helen Carter | 10 Sep 2026 | Agreed | 6 | Yes | OK | ||||||||||
| EXAMPLE | S04-08 | Marta Silva | Marketing Executive, Marketing | Active | marta.silva | Personal | Promotions editor | 20 Apr 2026 | Revoke | No sign-in since April; promotions are now set up by the online merchandisers. | SYS-04 | Helen Carter | 10 Sep 2026 | Agreed | 134 | Dormant | Dormant | Yes | Dormant | 1 | 5 | OK | ||||
| EXAMPLE | S04-09 | No match in HR | No match in HR | j.harper | Privileged | Store administrator | 14 Jan 2026 | Revoke | Console account whose email matches no current or former employee. Nobody claims it. | SYS-04 | Helen Carter | 10 Sep 2026 | Agreed | 230 | Dormant | Orphan | Yes | Orphan | 1 | 6 | OK |
HR Leavers
HR's list of people who have left since the last campaign. An entry whose person is here, with a leaving date on or before the As-at date, is flagged Leaver.
| Example | Name (as in the extracts) | Department | Leaving date | Entries still held (calc) | Of those, not revoked (calc) | Notes |
|---|---|---|---|---|---|---|
| EXAMPLE | Kieran Walsh | IT | 30 Jun 2026 | 1 | 0 | EXAMPLE: administrator account still active in SYS-03 (entry S03-12). |
| EXAMPLE | Chloe Dunn | Online Sales | 17 Jul 2026 | 0 | 0 | EXAMPLE: left before the campaign; no access found in the detailed systems. |
| EXAMPLE | Peter Lang | Finance | 7 Aug 2026 | 0 | 0 | EXAMPLE: left before the campaign; no access found in the detailed systems. |
Typed Totals
Counts for a system whose entries are not on the Entries sheet (see Instructions: sample plus totals). The System Summary sheet adds them to the entries.
| Example | System ID | Entries reviewed | Keep | Modify | Revoke | Cannot decide | Leavers | Dormant | Orphan | SoD conflicts | Where the entry-level detail is kept | Check (calc) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | SYS-01 | 164 | 139 | 11 | 12 | 2 | 3 | 6 | 1 | 1 | EXAMPLE: the ERP provider's user report (P06 SUP-004), returned with decisions and filed with the campaign evidence. The SoD conflict: the accounts payable supervisor could create or change suppliers and their bank details and approve payments (P02 SOD-FI-01, rated High); separated by a Modify; no exception. | OK |
| EXAMPLE | SYS-02 | 212 | 188 | 6 | 18 | 0 | 7 | 9 | 0 | 0 | EXAMPLE: the admin console export, one file per warehouse, with decisions, filed with the campaign evidence. | OK |
| EXAMPLE | SYS-05 | 96 | 80 | 4 | 12 | 0 | 2 | 4 | 0 | 0 | EXAMPLE: the permissions report, with decisions, filed with the campaign evidence. | OK |
Reviewer Progress
One row per reviewer, named exactly as in the Reviewer assigned column. Counts come from the Entries sheet. The quality signals are AR-09's rubber-stamp checks; numbers match the Instructions sheet.
| Example | Reviewer | Role and what they review | Assigned (calc) | Decided (calc) | Keep (calc) | Modify (calc) | Revoke (calc) | Cannot decide (calc) | Decided (%, calc) | Keep (%, calc) | Time spent reviewing (minutes) | Seconds per decision (calc) | Leavers or dormant kept (calc) | Privileged or generic kept without an owner (calc) | Self-review entries (calc) | Quality signals (calc) | Notes |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | Mark Ellis | Head of IT — system owner, SYS-03 | 12 | 12 | 8 | 1 | 3 | 0 | 100% | 67% | 35 | 175 | 0 | 0 | 0 | None | |
| EXAMPLE | Helen Carter | Chief Operating Officer — system owner, SYS-04 | 8 | 8 | 6 | 0 | 2 | 0 | 100% | 75% | 20 | 150 | 0 | 0 | 0 | None | |
| EXAMPLE | Ruth Okafor | Head of Information Security — second reviewer; reviews the two system owners' own access | 3 | 3 | 3 | 0 | 0 | 0 | 100% | 100% | 10 | 200 | 0 | 0 | 0 | None |
System Summary
System summary
Every figure adds the rows on the Entries sheet to the counts on the Typed Totals sheet, so it covers the whole campaign. Use it in the Access Review Outcome Report Template.
Results by system
| System ID | System | Rows on Entries | Typed entries | Entries reviewed | Keep | Modify | Revoke | Cannot decide | No decision yet | Leavers | Dormant | Orphan | SoD conflicts | Removals to track | Check |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| SYS-01 | ERP (hosted; P06 SUP-004) | 0 | 164 | 164 | 139 | 11 | 12 | 2 | 0 | 3 | 6 | 1 | 1 | 23 | OK |
| SYS-02 | Warehouse management system | 0 | 212 | 212 | 188 | 6 | 18 | 0 | 0 | 7 | 9 | 0 | 0 | 24 | OK |
| SYS-03 | Directory administrator groups | 14 | 0 | 14 | 10 | 1 | 3 | 0 | 0 | 1 | 0 | 1 | 0 | 4 | OK |
| SYS-04 | Online ordering admin console | 9 | 0 | 9 | 7 | 0 | 2 | 0 | 0 | 0 | 1 | 1 | 0 | 2 | OK |
| SYS-05 | Shared finance drive | 0 | 96 | 96 | 80 | 4 | 12 | 0 | 0 | 2 | 4 | 0 | 0 | 16 | OK |
| All systems | 23 | 472 | 495 | 424 | 22 | 47 | 2 | 0 | 13 | 20 | 3 | 1 | 69 |
|---|
EXAMPLE: SYS-03 and SYS-04 come from the Entries sheet, the other systems from the Typed Totals sheet. Leavers, dormant and orphan accounts are within Revoke.
Campaign at a glance
| Measure | Result | What it means | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Entries reviewed | 495 | 495 in the EXAMPLE. | |||||||||||||
| Revoke and Modify decisions to track | 69 | Paste the Removals Export into the Access Review Findings & Revocation Tracker (AR-07); its ARM-02 measures them. | |||||||||||||
| ARM-03 Access that should not have existed | 36 | Leaver, dormant and orphan accounts found in the campaign. Target: falling campaign on campaign. | |||||||||||||
| Segregation-of-duties conflicts found | 1 | Handle each with the P02 Segregation of Duties Conflict Matrix and, where accepted, an exception (AR-08). | |||||||||||||
| Cannot decide, passed to the system owner | 2 | Decided by the system owner within 2 working days; never Keep by default. | |||||||||||||
| Entries with no decision yet | 0 | Detailed entries only. After the deadline each is chased; none is kept by default (AR-05). | |||||||||||||
| Entries with a check to resolve | 0 | Any row on the Entries sheet whose Entry check does not say OK. | |||||||||||||
| Reviewers with a quality signal | 0 | Rubber-stamp signals on the Reviewer Progress sheet (AR-09). | |||||||||||||
| Ready to close? | Ready to close | Every entry decided, every check OK and no reviewer flagged. Removals are confirmed in the tracker before the close date. | |||||||||||||
Campaign sign-off (AR-09, AR-10)
| Item | Entry | ||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Quality check done by (name, role) and date | [[Name, role, YYYY-MM-DD]] | ||||||||||||||
| Rubber-stamp signals found and what was done | [[e.g. none; or reviewer re-did their list on YYYY-MM-DD]] | ||||||||||||||
| Campaign closed by (name, role) and date | [[Name, role, YYYY-MM-DD]] | ||||||||||||||
Removals Export
Calculated: every Revoke and Modify on the Entries sheet, in order. Copy columns B to L and paste them as values into the Access Review Findings & Revocation Tracker's Removals sheet, from its Removal ID column.
| Entry row (calc) | Removal ID | Campaign | Entry ID | System ID | Account | Person | Decision | Type | Privileged | Decided on | Decision deadline | Reason |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 5 | UAR-2026-Q3-R01 | UAR-2026-Q3 | S03-05 | SYS-03 | adm-dmorgan | Dan Morgan | Modify | Excess permission | Yes | 8 Sep 2026 | 15 Sep 2026 | Keep reset and unlock. Creating accounts belongs to the joiner process: remove that delegation. |
| 12 | UAR-2026-Q3-R02 | UAR-2026-Q3 | S03-12 | SYS-03 | adm-kwalsh | Kieran Walsh | Revoke | Leaver | Yes | 8 Sep 2026 | 15 Sep 2026 | Left on 2026-06-30 (HR leavers list). His everyday account was disabled; this administrator account was missed. |
| 13 | UAR-2026-Q3-R03 | UAR-2026-Q3 | S03-13 | SYS-03 | adm-migration | No match in HR | Revoke | Orphan | Yes | 8 Sep 2026 | 15 Sep 2026 | No owner found. Created for the 2025 server migration and never removed. |
| 14 | UAR-2026-Q3-R04 | UAR-2026-Q3 | S03-14 | SYS-03 | adm-rpatel | Ravi Patel | Revoke | No longer needed | Yes | 8 Sep 2026 | 15 Sep 2026 | Moved from infrastructure to application support in May; no longer administers servers. |
| 22 | UAR-2026-Q3-R05 | UAR-2026-Q3 | S04-08 | SYS-04 | marta.silva | Marta Silva | Revoke | Dormant | Yes | 10 Sep 2026 | 15 Sep 2026 | No sign-in since April; promotions are now set up by the online merchandisers. |
| 23 | UAR-2026-Q3-R06 | UAR-2026-Q3 | S04-09 | SYS-04 | j.harper | No match in HR | Revoke | Orphan | Yes | 10 Sep 2026 | 15 Sep 2026 | Console account whose email matches no current or former employee. Nobody claims it. |
Lists
| Decision | AccountType | EmploymentStatus | SecondReview | Scope | ScopeMonths | RemovalType |
|---|---|---|---|---|---|---|
| Keep | Personal | Active | Agreed | Privileged and administrator access, all systems | 3 | Leaver |
| Modify | Privileged | Leaver | Challenged | Systems supporting a critical service (or a critical or important function, DORA; or cardholder data, PCI DSS) | 6 | Dormant |
| Revoke | Generic | Long-term leave | Not needed | All other in-scope systems | 12 | Orphan |
| Cannot decide | Service | Contractor | Excess permission | |||
| Third-party | Third party | SoD conflict | ||||
| No match in HR | No longer needed |
Definitions
Definitions
| Term | Meaning in this workbook |
|---|---|
| Campaign | One round of access review across the systems in scope, from the extract to sign-off, with its own ID (for example UAR-2026-Q3). |
| Entry | One account holding one permission (a role, group or set of rights) in one system. A person with three roles in a system has three entries. |
| Extract | The list of who has access, taken from the system on a stated date (AR-03): the extract must be complete and taken on a stated date; the reviewer must see names, roles, permissions and last sign-in. |
| Decision — Keep | Access is needed and the permissions are right. |
| Decision — Modify | Access is needed but some permissions are not: remove the excess. |
| Decision — Revoke | Access is not needed: remove it. |
| Decision — Cannot decide | The reviewer does not know the person or the permission: it goes to the system owner within [[2]] working days, never to Keep by default. |
| Account type — Personal | Belongs to one named employee or contractor for their own work. Owner: the person; their line manager answers for the need. |
| Account type — Privileged | Can change the system, its settings, its users or its security: administrator groups, super-user roles, database owners. Owner: a named person, even where the account is separate from their personal account (AR-06). |
| Account type — Generic | Used by more than one person, or by a role rather than a person: a warehouse terminal login, a shared mailbox with sign-in, a training account. Owner: a named manager who answers for every use of it (AR-06). |
| Account type — Service | Used by software, not a person: an interface between two systems, a scheduled job, a backup agent. Owner: a named technical owner who knows what uses it (AR-06). |
| Account type — Third-party | Held by someone outside the organisation: a supplier's support staff, a contractor, an auditor, a customer on an admin console. Owner: the manager who manages that supplier or contract. |
| Dormant account | An account with no sign-in for more than the dormant setting (90 calendar days by default) before the extract date, or never signed in. Service accounts are not flagged: check their use in the system's logs. |
| Leaver | A person on the HR Leavers sheet with a leaving date on or before the As-at date. Any access they still hold should not exist. |
| Orphan account | An account nobody can be matched to: no current person and no named owner. Its Person reads "No match in HR". |
| Employment status | From HR on the extract date: Active, Leaver, Long-term leave, Contractor, Third party, No match in HR. Leaver also flags the entry, as does the HR Leavers sheet. |
| Should not exist | Leaver, orphan or dormant, in that order when more than one applies. Together they are ARM-03, access that should not have existed; each is raised as a finding (AR-08). |
| Self-review | Nobody may review their own access or the access of anyone who reviews theirs. Own access: the reviewer is the person on the entry. Reviews their reviewer: the person on the entry reviews some of the reviewer's own entries. |
| Privileged | An entry on a system whose scope is "Privileged and administrator access, all systems", or an account of type Privileged. Removal window 1 working day; other access 5 working days, counted from the campaign's decision deadline (AR-07). |
| Second review | Information security: samples decisions for quality, and reviews every privileged account a second time. Agreed, Challenged, or Not needed when information security was the reviewer. |
| Removal type | What a Revoke or Modify removes: Leaver, Dormant, Orphan, Excess permission, SoD conflict, No longer needed. Set by the flags and the SoD conflict column; the tracker uses it. |
| SoD conflict | Two duties one person should not hold together, from the P02 Segregation of Duties Conflict Matrix. Enter its conflict ID. |
| Rubber-stamp signals | A reviewer keeps 100% of a large list (more than [[25]] entries) in one sitting; Decisions made faster than [[5]] seconds each on average; Leavers or dormant accounts (no sign-in for [[90]] days) marked Keep; Privileged or generic accounts marked Keep without a named owner. Checked before the campaign is closed (AR-09). |
| Typed totals | Counts entered for a system whose entries are kept outside this workbook. Used in the EXAMPLE for SYS-01, SYS-02, SYS-05. |
| As-at date | The date flags and progress are measured against. Set on the Campaign sheet. |
| EXAMPLE row | A worked example: a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders, campaign UAR-2026-Q3, as at 2026-09-30. People are fictional. Delete before use. |
| AR-nn, ARM-nn, SYS-nn, PW-nn | Rule, measure, system and process weakness numbers in the Access Review Methodology and the pack's EXAMPLE. |
| (calc) | A column or cell the workbook calculates. Do not type or paste over it. |
Framework References
Framework references
These references indicate relevance only and do not reproduce the text of any standard.
| Framework | Reference | Supported by |
|---|---|---|
| ISO/IEC 27001:2022 | Annex A 5.18 — Access rights | Entries, decisions and reasons: access rights reviewed and changed at planned intervals |
| ISO/IEC 27001:2022 | Annex A 8.2 — Privileged access rights | Privileged system and account flags, information security second review, 1-working-day removal window |
| NIST CSF 2.0 | PR.AA-05 — “Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties” | Entries with decisions; SoD conflict column; Removals Export for least privilege |
| DORA — Delegated Regulation (EU) 2024/1774 | Article 21(c) — user accountability: generic and shared accounts limited, and users identifiable for their actions | Generic and service accounts need a named owner; orphan accounts flagged |
| DORA — Delegated Regulation (EU) 2024/1774 | Article 21(e) — account management: roles for granting, reviewing and revoking access; privileged access on a need-to-use basis; removal without undue delay; review at least every six months for systems supporting critical or important functions and at least yearly for others | Review frequency by scope on the Campaign sheet; removal windows; privileged access reviewed twice |
| PCI DSS v4.0.1 | Requirement 7.2.4 — user accounts and their access privileges, including third-party accounts, reviewed at least every six months | Every account reviewed, including third-party accounts, with review frequency by scope |
| PCI DSS v4.0.1 | Requirement 8.2.6 — inactive user accounts removed or disabled within 90 days | Dormant flag: no sign-in for 90 calendar days |
Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774; PCI DSS v4.0.1