{"description":"Runs on the existing system item. Review privileged, service, and emergency accounts on a system for continued business justification, supporting activity, and compensating monitoring. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[{"id":"e-pa-justification-pa-closure","source":"pa-justification","target":"pa-closure"}],"isPublic":true,"itemTypeSlug":"system","metadata":{"capabilities":["privileged-access-review"],"controlVerbs":{"UC-ACCESS-04":"operates"},"controls":["UC-ACCESS-04"],"department":"it","domains":["controls"],"kind":"privileged-access-review","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:privileged-access-review"}],"canonicalUrl":"https://workflow-library.com/all/?w=controls-system-privileged-access-review","contentDigest":"sha256:e3ac108af9cd689c1f752de579c7b9a732023b919cd218d036e128b47a82b175","prerequisites":{"anchorItemType":{"slug":"system"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:controls-privileged-access-authorization-model-management"}],"roles":[{"contribution":"expertise","description":"System owner and technical specialist. Test business justification and activity.","id":"reviewer-1","nodeIds":["pa-justification"]},{"contribution":"approval","description":"Independent system-risk reviewer. Approve privileged access record.","id":"reviewer-2","nodeIds":["pa-closure"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:privileged-access-review"}],"releaseId":"sha256:e3ac108af9cd689c1f752de579c7b9a732023b919cd218d036e128b47a82b175","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-system-privileged-access-review"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-system-privileged-access-review","source":"coworkcanvas-gallery","standards":[],"teams":["it"]},"name":"Privileged Access Review","nodes":[{"data":{"instructions":"**Objective**\nTest business justification and activity. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, role and permission definitions, group membership extracts, service and application account inventories, break-glass account registers, and the privileged-access policy.\n2. Use the privileged population, current role and job descriptions, activity and session logs for the period, change and incident records, and prior review justifications.\n\n**Procedure**\n1. State the privilege criteria before enumerating, extract membership for every qualifying role, include non-human and emergency accounts that user-focused extracts miss, and reconcile the population to an independent source.\n2. Test justification against the current role rather than the role at grant, inspect activity logs for accounts with no use and for use inconsistent with the stated purpose, and record logging gaps as gaps rather than as clean results.\n\n**Record in AssureSwarm**\n1. Capture the review period, privilege criteria applied, population per account class with extract dates, service and emergency accounts, reconciliation basis, and enumeration gaps. Also record privileged definition and population.\n2. Document the justification assessment per account, activity review coverage, dormant privileged accounts, activity inconsistent with stated purpose, logging gaps, and justifications relying only on representation.\n\n**Exit criteria**\nSystem owner and technical specialist provides expertise: Privilege is defined before enumeration, non-human and break-glass accounts are in scope, and enumeration gaps are declared rather than presumed empty. Justification is tested against current roles and observed activity, dormant and inconsistent accounts are surfaced, and logging gaps are declared rather than read as no findings.","kind":"task","label":"Test business justification and activity","requiredApprovals":1},"id":"pa-justification"},{"data":{"controls":["UC-ACCESS-04"],"instructions":"**Objective**\nApprove privileged access record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the justification assessment, removal tickets and post-removal extracts, monitoring and alerting configuration, session recording coverage, and the escalation route for accepted exceptions.\n2. Review all stage records, the enumeration and its reconciliation, justification results, activity coverage and logging gaps, removal evidence, monitoring tests, and accepted exceptions.\n\n**Procedure**\n1. Trace each removal decision to executed evidence, test that claimed compensating monitoring is actually configured and reviewed rather than merely available, and route accepted exceptions to the authorized approver before advancing.\n2. Trace dispositions to justification and activity evidence, verify retained access carries an expiry and tested monitoring, confirm logging gaps are owned, and return unevidenced monitoring claims with precise comments.\n\n**Record in AssureSwarm**\n1. Record the review outcome, removals traced to evidence, retained access with justification and expiry, compensating monitoring tested with configuration references, accepted exceptions and their approver, and residual gaps. Also record compensating monitoring detail.\n2. Capture the authorized reviewer, the summary, accepted outcome, effective review date, next review cadence, retained access with expiries, logging gaps with owners, and linked issues raised. Also record privileged access summary.\n\n**Exit criteria**\nIndependent system-risk reviewer provides approval: An approver accepts that retained privilege carries tested compensating monitoring rather than an assertion, removals are evidenced, and exceptions reached the authorized approver. The authorized reviewer accepts the record as evidence the privileged-access control operated for the period, and closure implies no assurance over account classes excluded from enumeration.","kind":"task","label":"Approve privileged access record","requiredApprovals":1},"id":"pa-closure"}],"sourceTemplateId":"workflow-library:controls-system-privileged-access-review"}
