{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:a7af16f97073e073ad464ca1ec5c0736dae8db8ef2ccdbccf8da2c2700053e2d","slug":"controls-user-access-review","url":"/assets/agent_workflow-controls-user-access-review-09945de9.b9f4ff692af3182a.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-user-access-review","description":"Runs on the existing Control item for UC-ACCESS-02 (user access review) — with UC-ACCESS-03 linked by item relationship — enriching that Control, never creating a duplicate; each quarterly or event-triggered cycle is a workflow instance attached to it, so archived instances accumulate as the de-facto control execution log. A decision-aware workflow covering entitlement extraction, manager certification, revocation, and independent verification. Consumes at start the prior cycle's scope-change carry-forward Issues and prior signed report (both attached to the same Control) plus the period's source-of-record entitlement extracts and period-end HR roster. Produces a signed, audit-ready recertification evidence package and control-owner report as the named deliverable. In scope: SOX-significant applications, systems holding data classified Confidential or above, identity infrastructure (directory, SSO, PAM), and privileged-reach platforms, across all account populations (standard, privileged, service, shared, emergency break-glass, third-party); triggered on scheduled cadence or by event (post-incident, auditor request). Out of scope: lifecycle provisioning and the privileged-access model itself — systemic findings hand off to the Joiner-Mover-Leaver Access Lifecycle (lifecycle gaps) and Privileged Access & Authorization Model Management (privileged-model findings) workflows.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-user-access-review","capabilities":[],"controls":["UC-ACCESS-02","UC-ACCESS-03"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:a7af16f97073e073ad464ca1ec5c0736dae8db8ef2ccdbccf8da2c2700053e2d","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-user-access-review","standards":["sox","iso-27001","nist-800-53"],"teams":["it","finance"]},"id":"wf:C12","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC12","slug":"controls-user-access-review","sourceIds":["aiuc-1","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"User Access Review & Recertification","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:34c64101a4c7fdffcef78476a8acc08f622b50a62f0956e5b1878e7fe7cd7fd6","properties":{},"sourceDetailPath":"/data/v1/records/wf-c12-d75a948f.json","sourceId":"wf:C12","targetDetailPath":"/data/v1/records/uc-uc-access-02-0132e278.json","targetId":"uc:UC-ACCESS-02","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:65e6929039ddbdd54312e30a9546e37a0f12f7fade9a92bbacc48432d82ab8d4","properties":{},"sourceDetailPath":"/data/v1/records/wf-c12-d75a948f.json","sourceId":"wf:C12","targetDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","targetId":"uc:UC-ACCESS-03","type":"operates"}],"schemaVersion":1}
