SportsFirst

Access review attestation tracker

Workflow automationWorkflow application4-6 week first releaseVerify or inspect

Problem

Once or twice a year, the information security officer exports the current user list for each system from the identity and access management tool, splits it by system owner and emails a spreadsheet: please confirm this list is still correct. Most owners reply "looks fine" without opening the file, because they are checking twenty rows for a system they rarely think about and the email is one of forty in an inbox. The confirmations pile up as email replies, not records against individual names, so when an internal auditor or an external assessor asks for evidence that access was actually reviewed, what exists is a folder of emails saying yes. Nobody can show which specific user was checked, by whom, or when.

Product idea

A review tool that turns the spreadsheet into a task list. Each system owner opens a link showing every current user on their system, one row per person, and must mark each row keep or revoke rather than approve the list as a whole. A revoke opens a ticket in the service desk queue rather than removing access itself, because turning off access is a separate job with its own owner. Every decision is stamped with the reviewer's name and the date. At the end of a review cycle, the information security officer exports a single attestation report covering every system, every user, every decision, in a form built to hand to an auditor. It does not read live from the identity and access management system and does not schedule review cycles automatically.

Who it is for

Information security officers running the review cycle, system owners doing the actual checking, and the head of IT who has to produce evidence of it. Service desk leads pick up the revoke tickets it creates.

Possible first version

A web tool seeded from a CSV export of users per system. It generates one review task per system owner with a fixed due date, a keep or revoke choice against each user, and a comment field. Revoked entries export as a list for the service desk rather than triggering removal automatically. At cycle close it produces a PDF attestation report per system and one combined summary. Out of scope for version one: no direct connection to the identity and access management system, no automatic revocation, and no recurring schedule, each cycle is started by hand.

Build classification
Workflow application
Rough effort
4-6 week first release
Roles involved
Information security officer, Head of IT, Service desk lead
Relevant to
Professional club, League office, Federation / governing body, Collegiate athletics
Systems in play
Identity and access management, Spreadsheets, Service desk and ticketing tools
Product framing
Verify or inspect

Questions we get asked

What do we need ready before the first review cycle?

A current export of users per system, in whatever format the identity and access management tool already produces, is enough to seed version one. It does not need to be perfect. Missing or duplicate entries surface as soon as an owner reviews their list, which is often the first time anyone has looked closely at it in a year. A named owner for each system is the other prerequisite, and in some organisations that list does not yet exist either.

Does this replace our identity and access management system?

No. The identity and access management system stays the system of record for who has access to what, and this stays a periodic check layered on top of it. Version one does not read from it automatically or write changes back into it; a revoke decision produces a ticket for someone else to act on. Whether a later version connects the two is worth revisiting once the review process itself is trusted and used.

Owners already reply "confirmed" to the spreadsheet without really checking it. Won't they just click through this the same way?

Some will, and no tool stops a reviewer determined not to look. What changes is the unit of decision: confirming one list with a single reply is easier to do without reading than marking forty individual rows, and a per-user, timestamped decision is a different piece of evidence than a one-line email even when the review itself was rushed. It raises the bar rather than guaranteeing scrutiny.

Who runs this day to day, and what does it cost them in time?

The information security officer typically owns the review cycle: starting it, chasing owners who miss the due date, and producing the final attestation report. That chasing is real work each cycle, not a one-off setup cost, because a review tool does not make a reluctant reviewer respond any faster than an email did. System owners spend whatever time they choose to spend per row, which is the point: the time is now visible rather than hidden inside a reply.

Is this your workflow?

Tell us one sports workflow that still runs on paper, spreadsheets, WhatsApp or an outdated system. We will map it and show you what a simpler product looks like.

Tell us about it

More in IT, data, compliance & knowledge