access-reviewlisted
Install: claude install-skill arthaszyb/bright-talent
# Access Review (Least-Privilege Policy)
Review service access-grant requests against the Acme Corp least-privilege
access policy. Apply the policy rules to the request and post a structured
pass/warn/fail review comment. **This skill never grants, approves, or revokes
access.** It produces a comment for a human access approver to act on.
## When to trigger
Trigger on:
- A bare access-request ID with review intent, e.g. "review access request
AR-2043 against the policy"
- Pasted access-request JSON/content with a request to review it
- "least-privilege check" / "access policy risk analysis" phrasing on a
specific request
Do **not** trigger (or trigger as review) on:
- Pure status queries ("what's the status of AR-2043") — that's a lookup,
not a review; a review re-runs the policy checks and produces a fresh comment
- Any request to grant, approve, or revoke access ("grant me admin on
checkout") — this skill has no grant/approve/revoke capability by design;
redirect the user to the access-management system's own approval action
- Questions about what the policy says in general — answer those from the
knowledge base without reviewing a specific request
## Inputs
- **Access request** (required): pasted JSON, or a request ID the user
supplies the JSON for. Expected fields: `request_id`, `requestor`,
`service`, `role`, `environment`, and (for production) `justification_ticket`,
`duration_days`, `manager_approved`.
- **Policy** (optional): defaults to the bu