The control auditors love to fail you on. Work through every grant, decide keep, modify, or revoke, capture who signed off, and export a clean record to CSV or Markdown — drop it straight into Notion as your evidence for the quarter.
| User | System | Role / grant | Last used | Decision |
|---|---|---|---|---|
Priya Shah | AWS · prod | AdministratorAccess | 2d ago | |
Marcus Lee | GitHub | Org admin | 6d ago | |
Dana Owusu | Okta | Super admin | 119d ago ⚠ | |
Sam Rivera | Stripe | Full access | 4d ago | |
Jordan Kim | Prod database | Read/write | 94d ago ⚠ | |
ci-deploy-bot svc · automation | AWS · prod | DeployRole | 1h ago | |
Alex Chen | Datadog | Admin | 61d ago | |
Robin Patel [email protected] (offboarded) | Salesforce | Standard | 142d ago ⚠ |
Four steps, repeated every 90 days. The whole point is a defensible, dated record — not a heroic one-time cleanup.
Export current access from each system — IdP, cloud, repos, prod DBs. Every standing grant in scope, including service accounts.
Each grant goes to the manager or system owner who can actually judge whether it's still needed. Don't self-review.
Keep, modify, or revoke. Revocations get a ticket and a timestamp. Stale grants (90+ days unused) default to revoke.
The reviewer signs off, the record is dated and stored. That artifact is your CC6.3 evidence for the audit window.
Uproot watches access continuously — flagging stale grants, dormant accounts, and over-provisioned roles the day they happen, and assembling the review record automatically. The quarterly export becomes a click, not a project.