Identity operations

War-game a privileged access review before standing admin becomes habit

War-game a privileged access review by testing whether role inventory, evidence rules, and revoke deadlines still shrink standing admin when several systems share break-glass paths and the audit date is close.

Privileged reviews fail when "reviewed" means a checkbox without a decision artifact, when managers dual-count Attestation as both approval and revoke proof, and when contractor admins live only in a spreadsheet. The review needs one written inventory of privileged roles, one owner who can deny continued access, and a documented consequence when a finding ages past the deadline.

Write the review packet before the calendar fills

List privileged roles by system, standing versus just-in-time use, last grant reason, manager of record, and evidence required to keep access. Attach open findings, overdue revokes, and any break-glass use in the last quarter. Name which roles are out of scope and why. If a shared cloud root account is omitted, show the residual risk in the same packet.

Decide the allow, revise, or hold outcomes in advance. Include the fields that compute overdue status so two reviewers reach the same label from the same exports.

Pressure the evidence, not the slide

ClaimEvidence requiredFail condition
Standing admin is requiredNamed tasks that fail without it in the next thirty daysTask list is empty or already covered by just-in-time access
Review is completeDecision artifact per role with keep or revokeCheckbox without a signed decision
Revoke is doneSystem export showing role removedTicket closed while export still shows membership
Break-glass is controlledLogged use with time-bound restoreShared password or unlogged use

Walk four cases in Pingpong: a contractor admin past end date, a production root shared by vendors, a manager who re-approves without reading the role description, and a request to skip a cloud account because the console login is rare. For each case, start from the documented review language. Ask who can extend a deadline and which export proves revoke. Any step that depends on an unnamed person becomes a review condition.

Replay one prior audit finding under the proposed rules. If the finding would still age without a revoke owner, revise the rules before calling the cycle complete.

Pair this review with the identity ops lead seat and a SCIM provisioning rollout. Session leftovers after revoke often need a session timeout stress test. More operating decisions live in the war-game decisions hub.

Close the cycle only when keep and revoke labels can be reproduced from stored exports without a verbal override.