Reviewing a person's or group's access
Review the responsibilities and rules attached to a person or group to confirm the access is still appropriate.
When to use this
- Use it in periodic reviews.
- Use it when someone changes function.
- Use it after incidents, audits, or the end of a project.
Before you start
- Find the user or group.
- Have defined review criteria.
- Consult the data domain's owner when in doubt.
Step by step
- Open Users, Groups, and Profiles.
- Search for the person or group.
- Review the assigned roles.
- Review the groups the person belongs to.
- Open Data Governance to review the related rules.
- Remove or adjust whatever has no current justification.
- Record the conclusion according to your organization's process.
What happens next
- Effective access is aligned with the current function.
- Changes are recorded in the audit trail.
- Affected users may need to refresh the Console.
Common errors
- Reviewing only the user and forgetting the groups.
- Removing access used by an automation or a critical process without checking the impact.
- Keeping access because nobody knows who owns it.
Good practice
- Run reviews by group and by data domain.
- Prioritize broad, sensitive, or non-expiring access.
- Document the decisions behind keeping exceptions.
Next steps
Was this page helpful?
Report a problem on this pageDo not send passwords, keys, tokens, or customer data.