Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

User Access Review Workbook (SOC 2 / ISO 27001)

Join app user lists with the HR list, flag what needs a decision, keep the evidence.

Security No upload Free preview, no sign-upIncluded in your pass Premium tool Premium pass: ₹799 for 30 days

Free preview.

  • Free preview: the finding counts of all your files and the first flagged accounts (up to 10).
  • Locked until you unlock it: download.
  • Unlock: Premium pass, ₹799 for 30 days, a one-time payment that never renews.

Ways to unlock shows how to get the full result.

See passes (opens in a new tab)

Printing this result is locked in the free preview.

Findings

The files are read in this browser and are never uploaded. Only the settings below are remembered here, never the lists.

Review settings

Words that mark admin roles and shared accounts

1 HR list

An export of current staff and leavers with an employee ID or e-mail, the name, the employment status or leaving date, and the manager.

2 Application user lists

The user list of each application: the account or user name, and where the export has them the e-mail, employee ID, name, role, last sign-in and account status.

    3 Completed workbook after the managers’ review

    Read the workbook back once the managers have filled in their decisions: the summary then lists what was kept, changed and removed, and what is still open.

    Findings

    Add the HR list and at least one application’s user list.

      Next steps

      About the User Access Review Workbook (SOC 2 / ISO 27001)

      A user access review checks, application by application, that every account belongs to someone who still needs it, with the right rights. Auditors ask for it as evidence for SOC 2 criteria CC6.2 and CC6.3 and for ISO/IEC 27001 Annex A 5.18. This tool prepares the review from files you can take out of your systems: the HR list of current staff and leavers, and the user list of each application.

      Accounts are joined to people by employee ID or e-mail, then by user name (jsmith, john.smith) or name, with the match shown so you can check it. They are flagged when they belong to a leaver, match nobody in the HR list, look like generic or team accounts (info@, admin, svc-…), have administrator rights, or were not used for longer than the period you set. You get a review workbook with a sheet per application in which each manager marks Keep, Change or Remove with a date, and a PDF summary to keep as evidence. When the managers are done, read the completed workbook back for a summary of the decisions and of what is still open.

      The free preview joins all your files and shows the counts and the first flagged accounts; the workbook and the PDF need a Premium pass. The files are read in your browser and never uploaded.

      How to use it

      1. Set the review date (leavers and unused accounts are judged on it) and how many days without a sign-in count as unused.
      2. Choose the HR list (Excel or CSV) and confirm its columns: employee ID or e-mail, name, employment status or leaving date, and manager.
      3. Add the user list of each application and confirm its columns: the account or user name and, where the file has them, e-mail, employee ID, name, role, last sign-in and account status. Name the application and its owner, who reviews accounts that match nobody.
      4. Read the findings, starting with leavers’ accounts and accounts that match nobody. With a Premium pass, download the review workbook and send each manager their sheet; without one, the free preview shows the counts and the first flagged accounts.
      5. When the managers have filled in their decisions, read the completed workbook back and download the PDF summary for your evidence folder, with the workbook (with a Premium pass).

      Examples

      The example files
      Input
      An HR list of 9 people (2 leavers) and the user lists of a cloud console (7 accounts) and a finance system (6 accounts)
      Result
      13 accounts, 9 matched to people, 10 flagged: 2 leavers’ accounts, 2 matching nobody, 2 shared, 3 with administrator rights, 3 not used for more than 90 days, 1 with no sign-in and 1 matched by user name only.

      Press Try the example on the page, or download the Example files to see the formats.

      Matching without e-mail addresses
      Input
      Finance export with the login “lmartin” and no e-mail; HR list with “Lucas Martin”
      Result
      Matched to Lucas Martin by user name, marked “matched by name only” so the reviewer checks it.

      Common uses

      • The quarterly or half-yearly access review for a SOC 2 Type 2 period.
      • Checking that leavers’ accounts were removed from every application.
      • Finding forgotten, shared and test accounts before an ISO/IEC 27001 audit.
      • Reviewing administrator rights across cloud consoles, finance and HR systems.

      What the findings mean

      • Belongs to a leaver: the HR list says the person has left, or the leaving date is on or before the review date, and the account is not disabled.
      • No match in the HR list: nobody in the HR list has its employee ID, e-mail, user name or name. Often a former contractor, a test account or a service account.
      • Shared or generic account: a name such as info, support, admin, test or svc-backup. It needs a named owner, or personal accounts instead.
      • Administrator or privileged access: the role contains a word such as admin, owner or super user; the list of words is yours to edit.
      • Not used recently and No sign-in recorded: from the last sign-in column, compared with the review date.
      • Matched by name only: the match came from the user name or name, not from an ID or e-mail; check it.
      • Second account of the same person in one application.

      The review workbook

      The workbook has a summary, one sheet per application with every account (flagged ones coloured), the person it matched, the findings and what to do, the reviewer (the person’s manager from the HR list, or the application owner), and four columns for the review: Decision (a drop-down: Keep, Change, Remove), Decision date, Reviewed by and Comment, plus Change done on for whoever changes the account. A findings sheet lists every flagged account, a leavers sheet the people who still have access, and the last sheet explains how to complete the review.

      Evidence for SOC 2 and ISO 27001

      Auditors usually ask for the user lists the review used, the list of people, the decisions with who made them and when, and proof that the changes were made. Keep the original exports, the completed workbook and the PDF summary together. How often to review is your decision: many organisations review privileged and production access every quarter and other access twice a year, as the access control policy from the Information Security Policy Generator suggests.

      Limitations

      • It is only as complete as the exports: an application left out, or an export without disabled accounts, is not reviewed.
      • Matching by user name and name can be wrong for common names; such matches are marked so the reviewer checks them.
      • Flags are suggestions for the reviewer, not decisions: a dormant account may be needed, and an admin role may be right.
      • It does not connect to your systems or change any account; the changes are made in each application.

      Privacy

      The HR list and the user lists contain personal data. They are read in this browser and never uploaded, and they are not kept: only the settings (organisation, review name, the number of days and your lists of words) are remembered in this browser.

      Frequently asked questions

      What do I get without a pass?

      Without a pass, User Access Review Workbook (SOC 2 / ISO 27001) shows the finding counts of all your files and the first flagged accounts (up to 10). Until you unlock it, the result can’t be downloaded. A Premium pass, a one-time payment that never renews, unlocks the full result. The pricing page lists the passes and their prices.

      Which columns does the HR list need?

      At least an employee ID, an e-mail address or a name for each person. For the flags it also helps to have the employment status or the leaving date, and the manager, who becomes the reviewer of the person’s accounts. Column headings are matched automatically and you can correct them.

      Our file writes dates like 03/04. Is that the 3rd of April or the 4th of March?

      The tool looks at all the dates in the column: a value such as 25/04 shows that the day comes first. When every value is ambiguous, choose day/month or month/day in the import panel. Dates written year first (YYYY-MM-DD) and dates with month names are always read correctly.

      How is a leaver decided?

      From the HR list: a status such as Leaver, Terminated, Inactive or Resigned, or a leaving date on or before the review date. A leaver’s account counts only when the export does not show it as disabled.

      What does reading the completed workbook back give?

      A summary of the decisions per application (kept, to change, to remove, no decision), the flagged accounts still without a decision, and the changes and removals not recorded as done. It goes into the PDF summary as evidence.

      Are the files uploaded?

      No. They are read in your browser and the workbook and the PDF are made there. Nothing is sent to a server, and the lists are not kept after you close the page.

      Quick answers and tool search

      Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.