Access review attestation tracker
Problem
Once or twice a year, the information security officer exports the current user list for each system from the identity and access management tool, splits it by system owner and emails a spreadsheet: please confirm this list is still correct. Most owners reply "looks fine" without opening the file, because they are checking twenty rows for a system they rarely think about and the email is one of forty in an inbox. The confirmations pile up as email replies, not records against individual names, so when an internal auditor or an external assessor asks for evidence that access was actually reviewed, what exists is a folder of emails saying yes. Nobody can show which specific user was checked, by whom, or when.
Product idea
A review tool that turns the spreadsheet into a task list. Each system owner opens a link showing every current user on their system, one row per person, and must mark each row keep or revoke rather than approve the list as a whole. A revoke opens a ticket in the service desk queue rather than removing access itself, because turning off access is a separate job with its own owner. Every decision is stamped with the reviewer's name and the date. At the end of a review cycle, the information security officer exports a single attestation report covering every system, every user, every decision, in a form built to hand to an auditor. It does not read live from the identity and access management system and does not schedule review cycles automatically.
Who it is for
Information security officers running the review cycle, system owners doing the actual checking, and the head of IT who has to produce evidence of it. Service desk leads pick up the revoke tickets it creates.
Possible first version
A web tool seeded from a CSV export of users per system. It generates one review task per system owner with a fixed due date, a keep or revoke choice against each user, and a comment field. Revoked entries export as a list for the service desk rather than triggering removal automatically. At cycle close it produces a PDF attestation report per system and one combined summary. Out of scope for version one: no direct connection to the identity and access management system, no automatic revocation, and no recurring schedule, each cycle is started by hand.
- Build classification
- Workflow application
- Rough effort
- 4-6 week first release
- Roles involved
- Information security officer, Head of IT, Service desk lead
- Relevant to
- Professional club, League office, Federation / governing body, Collegiate athletics
- Systems in play
- Identity and access management, Spreadsheets, Service desk and ticketing tools
- Product framing
- Verify or inspect
Questions we get asked
What do we need ready before the first review cycle?
A current export of users per system, in whatever format the identity and access management tool already produces, is enough to seed version one. It does not need to be perfect. Missing or duplicate entries surface as soon as an owner reviews their list, which is often the first time anyone has looked closely at it in a year. A named owner for each system is the other prerequisite, and in some organisations that list does not yet exist either.
Does this replace our identity and access management system?
No. The identity and access management system stays the system of record for who has access to what, and this stays a periodic check layered on top of it. Version one does not read from it automatically or write changes back into it; a revoke decision produces a ticket for someone else to act on. Whether a later version connects the two is worth revisiting once the review process itself is trusted and used.
Owners already reply "confirmed" to the spreadsheet without really checking it. Won't they just click through this the same way?
Some will, and no tool stops a reviewer determined not to look. What changes is the unit of decision: confirming one list with a single reply is easier to do without reading than marking forty individual rows, and a per-user, timestamped decision is a different piece of evidence than a one-line email even when the review itself was rushed. It raises the bar rather than guaranteeing scrutiny.
Who runs this day to day, and what does it cost them in time?
The information security officer typically owns the review cycle: starting it, chasing owners who miss the due date, and producing the final attestation report. That chasing is real work each cycle, not a one-off setup cost, because a review tool does not make a reluctant reviewer respond any faster than an email did. System owners spend whatever time they choose to spend per row, which is the point: the time is now visible rather than hidden inside a reply.
Is this your workflow?
Tell us one sports workflow that still runs on paper, spreadsheets, WhatsApp or an outdated system. We will map it and show you what a simpler product looks like.
Tell us about itMore in IT, data, compliance & knowledge
- Certificate and domain renewal obligation registerA register of every TLS certificate and domain name renewal date across the technology estate, with a named owner and escalation before one lapses and takes a service down.
- Data retention and deletion obligation registerA register that tracks retention deadlines for datasets holding personal data across the technology estate and escalates to a named owner before deletion or review falls overdue.
- Integration heartbeat monitor and owner escalation boardA live board of every integration's last successful run that escalates to a named owner before a missed sync turns into a bad report or an angry ticket.