Operations & Delivery
Who has access to what — the single most common audit finding, solved properly.
Stale access for leavers shows up in almost every security review ever run. This is the joiner-mover-leaver lifecycle, done as a discipline rather than a scramble.
Other typical workflows in this domain: project & engagement delivery management, vendor & supplier management, and business continuity planning.
Sample workflow: IT access management & provisioning
Automation = deterministic, rule-based. AI = judgement at the step level — drafting, scoring, matching. Human = decision, relationship, or anything that sets a precedent.
01Role definition
HumanAccess defined per role, not per individual request.
02Single sign-on
AutomationSystems brought under SSO and MFA wherever supported.
03Joiner provisioning
AutomationJoiners provisioned from the role profile before day one.
04Exceptions
AIAccess above the role profile requested and routed for approval, with a reason recorded.
05Least privilege
AutomationGrants scoped to least privilege; admin rights rationed and logged.
06Mover process
AutomationRole changes trigger re-profiling — old access removed, not just new added.
07Privileged access
AutomationPrivileged accounts inventoried, vaulted, and logged.
08Recertification
AIPeriodic review compiled for owners to re-attest who should have access.
09Third-party access
AutomationSupplier and contractor access made time-bound and scoped.
10Leaver revocation
AutomationAccess revoked same-day per the offboarding checklist, verified not assumed.
11Anomaly review
AIAccess and auth logs reviewed; anomalies routed to security.
12Reconciliation
AutomationAccess map reconciled with the subscription register.