War-game a privileged access review by testing whether role inventory, evidence rules, and revoke deadlines still shrink standing admin when several systems share break-glass paths and the audit date is close.
Privileged reviews fail when "reviewed" means a checkbox without a decision artifact, when managers dual-count Attestation as both approval and revoke proof, and when contractor admins live only in a spreadsheet. The review needs one written inventory of privileged roles, one owner who can deny continued access, and a documented consequence when a finding ages past the deadline.
Write the review packet before the calendar fills
List privileged roles by system, standing versus just-in-time use, last grant reason, manager of record, and evidence required to keep access. Attach open findings, overdue revokes, and any break-glass use in the last quarter. Name which roles are out of scope and why. If a shared cloud root account is omitted, show the residual risk in the same packet.
Decide the allow, revise, or hold outcomes in advance. Include the fields that compute overdue status so two reviewers reach the same label from the same exports.
Pressure the evidence, not the slide
| Claim | Evidence required | Fail condition |
|---|---|---|
| Standing admin is required | Named tasks that fail without it in the next thirty days | Task list is empty or already covered by just-in-time access |
| Review is complete | Decision artifact per role with keep or revoke | Checkbox without a signed decision |
| Revoke is done | System export showing role removed | Ticket closed while export still shows membership |
| Break-glass is controlled | Logged use with time-bound restore | Shared password or unlogged use |
Walk four cases in Pingpong: a contractor admin past end date, a production root shared by vendors, a manager who re-approves without reading the role description, and a request to skip a cloud account because the console login is rare. For each case, start from the documented review language. Ask who can extend a deadline and which export proves revoke. Any step that depends on an unnamed person becomes a review condition.
Replay one prior audit finding under the proposed rules. If the finding would still age without a revoke owner, revise the rules before calling the cycle complete.
Pair this review with the identity ops lead seat and a SCIM provisioning rollout. Session leftovers after revoke often need a session timeout stress test. More operating decisions live in the war-game decisions hub.
Close the cycle only when keep and revoke labels can be reproduced from stored exports without a verbal override.