Reusable operating kit
Access handoff card
Prepare named access, recovery, and departure checks for one critical service.
What the completed kit should do
A repeatable access change record that does not expose credentials.
Capture these facts in your approved system
- Service and business job
- Person, role, approval owner, and access start date
- Authentication method and business-controlled recovery owner
- Access changed, removed, or retained with reason
- Verifier, verification date, and unresolved exception
Use the structure in this order
- 01
Approve the smallest workable role.
- 02
Create or update a named account.
- 03
Confirm strong authentication and recovery.
- 04
Verify access from the person's normal work path.
- 05
Close prior or unnecessary access and record the result.
Close the loop
The intended person can work, the business can recover the account, and unnecessary access is removed.
Keep sensitive material out of this site
- Record the control result, never the password, token, recovery code, security answer, or private key.