← ClaudeAtlas

access-reviewlisted

Review an Acme Corp service access-grant request against the least-privilege access policy. Use ONLY when the user explicitly asks to review, risk-analyze, or policy-check a SPECIFIC access request, identified by a request ID such as AR-2043 accompanied by review intent, or pasted access-request JSON (fields like request_id, requestor, service, role, environment, duration_days). Applies the least-privilege policy (role catalog, production time-boxing, privileged-PII manager approval) and renders a structured Markdown review comment. Do NOT use this skill for - access status lookups (e.g. "what's the status of AR-2043" - answer directly), requests to grant, approve, or revoke access (decline - this DE never makes access decisions), listing or searching access requests, or general questions about what the policy says (answer those from the knowledge base without reviewing any request). Comment-only output; the grant decision stays with a human approver.
arthaszyb/bright-talent · ★ 0 · Code & Development · score 73
Install: claude install-skill arthaszyb/bright-talent
# Access Review (Least-Privilege Policy) Review service access-grant requests against the Acme Corp least-privilege access policy. Apply the policy rules to the request and post a structured pass/warn/fail review comment. **This skill never grants, approves, or revokes access.** It produces a comment for a human access approver to act on. ## When to trigger Trigger on: - A bare access-request ID with review intent, e.g. "review access request AR-2043 against the policy" - Pasted access-request JSON/content with a request to review it - "least-privilege check" / "access policy risk analysis" phrasing on a specific request Do **not** trigger (or trigger as review) on: - Pure status queries ("what's the status of AR-2043") — that's a lookup, not a review; a review re-runs the policy checks and produces a fresh comment - Any request to grant, approve, or revoke access ("grant me admin on checkout") — this skill has no grant/approve/revoke capability by design; redirect the user to the access-management system's own approval action - Questions about what the policy says in general — answer those from the knowledge base without reviewing a specific request ## Inputs - **Access request** (required): pasted JSON, or a request ID the user supplies the JSON for. Expected fields: `request_id`, `requestor`, `service`, `role`, `environment`, and (for production) `justification_ticket`, `duration_days`, `manager_approved`. - **Policy** (optional): defaults to the bu