access-review

Featured

Conduct periodic access reviews and certifications. Implement access governance and recertification workflows. Use when managing access compliance.

Code & Development 46,937 stars 6838 forks Updated today MIT

Install

View on GitHub

Quality Score: 98/100

Stars 20%
100
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
80
License 10%
100
Description 5%
100

Skill Content

# Access Review Implement periodic access review processes for AWS IAM, GitHub, Okta, and other identity providers, including automated reporting, certification workflows, and unused permission detection. ## Access Review Process ```yaml access_review_workflow: 1_scope: actions: - Define systems in scope for the review cycle - Identify review owners (managers, system owners) - Set review timeline and deadlines - Generate access inventory from all identity sources frequency: privileged_access: Quarterly standard_access: Semi-annually service_accounts: Quarterly api_keys: Monthly 2_extract: actions: - Pull current access data from all systems - Correlate identities across platforms (SSO mapping) - Enrich with last login and activity data - Flag accounts for review (inactive, over-privileged, orphaned) 3_review: actions: - Assign review items to appropriate managers - Manager certifies each user's access (approve/revoke/modify) - Risk-based prioritization (privileged users reviewed first) - Escalate non-responses after deadline decisions: approve: "Access is appropriate for current role" modify: "Access needs adjustment (reduce/change scope)" revoke: "Access is no longer needed" 4_remediate: actions: - Revoke access flagged for removal - Modify access as directed by reviewers - Document exceptions with justifica...

Details

Author
sickn33
Repository
sickn33/agentic-awesome-skills
Created
8 months ago
Last Updated
today
Language
Python
License
MIT

Bundled in these plugins

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Listed

it-access-review

Runs user access reviews and joiner-mover-leaver processing: reconciles entitlements against an authoritative people source, routes each item to the right approver, and closes the loop on revocations with evidence. Use when a periodic access recertification is due, when someone joins, changes role, or leaves, when an auditor asks who has access to a system, or when orphaned and privileged accounts need sweeping. Trigger on 'access review', 'user access recertification', 'joiner mover leaver', 'offboarding checklist', 'who has admin on X', 'orphaned accounts', 'entitlement review'. Not for granting a single new permission on request — that is it-service-desk-triage; not for deciding what a role should be entitled to in the first place, which is the role design that precedes this.

0 Updated 4 weeks ago
alihusains
Code & Development Listed

enterprise-access-governance-review

Enterprise access governance: roles, joiner-mover-leaver, access reviews, least privilege.

1 Updated today
SylphxAI
Code & Development Listed

access-review

Review an Acme Corp service access-grant request against the least-privilege access policy. Use ONLY when the user explicitly asks to review, risk-analyze, or policy-check a SPECIFIC access request, identified by a request ID such as AR-2043 accompanied by review intent, or pasted access-request JSON (fields like request_id, requestor, service, role, environment, duration_days). Applies the least-privilege policy (role catalog, production time-boxing, privileged-PII manager approval) and renders a structured Markdown review comment. Do NOT use this skill for - access status lookups (e.g. "what's the status of AR-2043" - answer directly), requests to grant, approve, or revoke access (decline - this DE never makes access decisions), listing or searching access requests, or general questions about what the policy says (answer those from the knowledge base without reviewing any request). Comment-only output; the grant decision stays with a human approver.

0 Updated 2 months ago
arthaszyb