1. Purpose
The Access Revocation Checklist provides a structured process for removing user, system, application, cloud, privileged, physical, and remote access when access is no longer required.
The objective is to ensure that access is:
- Revoked promptly
- Revoked from all relevant systems
- Based on an authorized trigger
- Verified after removal
- Supported by appropriate evidence
- Coordinated with credential and session management
- Addressed across cloud, SaaS, production, source-code, database, and physical environments
- Completed without leaving orphaned accounts, tokens, keys, or permissions
Core Principle
Identify → Authorize → Inventory → Revoke → Disable → Rotate → Verify → Record → Close
2. When to Use
Use this checklist when access must be removed because of:
☐ Employee termination
☐ Employee resignation
☐ Employee role change
☐ Department transfer
☐ Contractor termination
☐ Consultant termination
☐ Temporary access expiry
☐ Project completion
☐ Privileged access removal
☐ Security incident
☐ Suspected account compromise
☐ Access no longer required
☐ Supplier termination
☐ Application retirement
☐ Credential compromise
☐ Policy violation
☐ Long-term leave
☐ Contract expiry
☐ Other: __________________________
3. Access Revocation Information
| Field | Details |
|---|---|
| Revocation ID | |
| User/Account Name | |
| Employee/Contractor ID | |
| Department | |
| Current Role | |
| Manager/System Owner | |
| Revocation Trigger | |
| Effective Date | |
| Effective Time | |
| Risk Level | |
| Requested By | |
| Approved By | |
| IT Owner | |
| Security Reviewer | |
| Completion Date |
4. Revocation Trigger
Identify why access must be revoked.
☐ Termination
☐ Role change
☐ Temporary access expiry
☐ Project completion
☐ Access review finding
☐ Security incident
☐ Account compromise
☐ Policy violation
☐ Contract termination
☐ Supplier offboarding
☐ Business requirement changed
☐ System/application retirement
☐ Credential compromise
☐ Other: __________________________
Trigger Details
5. Authorization
Confirm that the revocation is authorized.
☐ Request received
☐ Request validated
☐ Identity verified
☐ Manager approval obtained where required
☐ System-owner approval obtained where required
☐ Security approval obtained where required
☐ Emergency revocation authorized where applicable
Requested By: ______________________
Approved By: _______________________
Date: ______________________________
6. Revocation Timing
Determine when access must be removed.
Required Revocation Date: __________________
Required Revocation Time: __________________
Time Zone: __________________
☐ Immediate revocation
☐ Same-day revocation
☐ Scheduled revocation
☐ Expiry-based revocation
☐ Other: __________________________
For high-risk situations, access should be removed as soon as reasonably required by the organization’s incident or access-management process.
7. Access Inventory
Identify all access associated with the user.
☐ Corporate identity
☐ Email
☐ SSO
☐ MFA
☐ VPN
☐ AWS/cloud
☐ GitHub/GitLab/Bitbucket
☐ CI/CD
☐ Production systems
☐ Databases
☐ SaaS applications
☐ Security tools
☐ Monitoring systems
☐ Ticketing systems
☐ CRM
☐ Finance systems
☐ HR systems
☐ Password manager
☐ API access
☐ Service accounts
☐ Physical access
☐ Other systems
Access Inventory
| System | Account | Access Type | Privileged | Revocation Required |
|---|---|---|---|---|
| ☐ | ☐ | |||
| ☐ | ☐ | |||
| ☐ | ☐ |
8. Corporate Identity
☐ User account disabled
☐ Account sign-in blocked
☐ SSO access removed
☐ Directory group memberships removed
☐ MFA registration addressed
☐ Authentication methods removed
☐ Recovery email/phone addressed
☐ Active sessions terminated where appropriate
☐ Refresh tokens invalidated where applicable
☐ Account status verified
9. Email Access
☐ Email account disabled
☐ Active sessions terminated
☐ Email tokens invalidated
☐ Mail forwarding reviewed
☐ Automatic forwarding removed
☐ Shared mailbox access removed
☐ Distribution groups reviewed
☐ Calendar access removed
☐ Delegated access removed
☐ Mailbox ownership transferred where required
10. VPN and Remote Access
☐ VPN account disabled
☐ VPN certificates revoked
☐ VPN groups removed
☐ Remote-access permissions removed
☐ Remote-access tokens revoked
☐ Remote sessions terminated
☐ Bastion/jump-host access removed
☐ Remote administration access removed
11. AWS / Cloud Access
If the user has cloud access:
☐ AWS IAM user disabled/deleted where appropriate
☐ IAM role assignments removed
☐ IAM group membership removed
☐ Access keys revoked
☐ Temporary credentials addressed
☐ MFA device addressed
☐ AWS SSO/Identity Center access removed
☐ Cloud administrator access removed
☐ Cloud console access removed
☐ CLI/API access removed
☐ Production cloud access removed
☐ Cloud ownership transferred where required
AWS Revocation Evidence
12. Other Cloud Platforms
Where applicable:
☐ Microsoft Azure access removed
☐ Google Cloud access removed
☐ Cloud organization membership removed
☐ Cloud IAM permissions removed
☐ Service-specific permissions removed
☐ Administrative roles removed
☐ API credentials revoked
13. Source-Code Access
☐ GitHub access removed
☐ GitLab access removed
☐ Bitbucket access removed
☐ Organization membership removed
☐ Repository permissions removed
☐ Branch permissions removed
☐ Code-owner permissions removed
☐ CI/CD access removed
☐ Deployment permissions removed
☐ Personal access tokens revoked
☐ SSH keys removed/revoked
☐ Code-signing access addressed
14. Production Access
If production access exists:
☐ Production account disabled
☐ Production role removed
☐ SSH access removed
☐ Bastion access removed
☐ Kubernetes access removed
☐ Production database access removed
☐ Production cloud permissions removed
☐ Monitoring access removed
☐ Administrative access removed
☐ Emergency access reviewed
☐ Active production sessions terminated where appropriate
Production Revocation
| System | Access | Revoked | Verified By |
|---|---|---|---|
| ☐ | |||
| ☐ | |||
| ☐ |
15. Privileged Access
If the user has administrative privileges:
☐ Administrator role removed
☐ Privileged groups removed
☐ Root-equivalent access removed
☐ Privileged cloud access removed
☐ Database administrator access removed
☐ Security administrator access removed
☐ Firewall/network administrator access removed
☐ Privileged sessions terminated
☐ Break-glass access reviewed
☐ Shared administrator credentials rotated where necessary
16. SaaS Applications
Review all SaaS platforms.
| Application | Account | Access | Revoked | Verified |
|---|---|---|---|---|
| ☐ | ☐ | |||
| ☐ | ☐ | |||
| ☐ | ☐ | |||
| ☐ | ☐ |
Consider:
- CRM
- ERP
- HR
- Finance
- Project management
- Customer support
- Security platforms
- Collaboration tools
- Password managers
- Analytics platforms
- Marketing platforms
- Ticketing platforms
17. Database Access
☐ Database account disabled
☐ Database roles removed
☐ Production database access removed
☐ Development database access removed where no longer required
☐ Read/write permissions removed
☐ Administrative permissions removed
☐ Database tokens/credentials revoked
☐ Connection strings reviewed where necessary
18. API Keys and Tokens
Identify non-password authentication mechanisms.
☐ API keys identified
☐ Personal access tokens identified
☐ OAuth tokens identified
☐ Access tokens revoked
☐ Refresh tokens revoked
☐ SSH keys revoked
☐ Certificates addressed
☐ Cloud access keys revoked
☐ Service credentials reviewed
☐ Shared credentials rotated where required
Credential Rotation Required?
☐ Yes
☐ No
Details
19. Secrets and Passwords
Assess whether the user knew or had access to shared secrets.
☐ Password-manager access removed
☐ Shared passwords reviewed
☐ Administrative passwords reviewed
☐ Service credentials reviewed
☐ Database credentials reviewed
☐ Cloud credentials reviewed
☐ API secrets reviewed
☐ Encryption-key access reviewed
☐ Secrets rotated where required
Do not store actual passwords, API keys, private keys, or secrets in this checklist.
20. MFA and Authentication Devices
☐ MFA device removed
☐ Authenticator registration removed
☐ Hardware security key recovered or invalidated
☐ Smart card revoked
☐ Recovery codes addressed
☐ Backup authentication methods removed
☐ Trusted devices removed
☐ Registered mobile number reviewed
21. Physical Access
☐ Office access card disabled
☐ Restricted-area access removed
☐ Data-center access removed
☐ Secure-area access removed
☐ Physical keys recovered
☐ Visitor privileges removed
☐ Parking/access privileges removed
☐ Other physical permissions removed
22. Customer and Supplier Systems
If external access exists:
☐ Customer portal access removed
☐ Supplier portal access removed
☐ Third-party collaboration access removed
☐ External administrative access removed
☐ Customer-specific accounts disabled
☐ Supplier-specific accounts disabled
☐ External contact ownership transferred
23. Mobile and Endpoint Access
☐ Corporate laptop access removed
☐ Endpoint management account removed
☐ Device certificates revoked
☐ Corporate applications removed where required
☐ Mobile access removed
☐ MDM access reviewed
☐ Remote-wipe capability considered where applicable
☐ Device ownership transferred or recovered
24. Active Sessions
Account disabling alone may not terminate all active sessions.
Where supported:
☐ Web sessions terminated
☐ VPN sessions terminated
☐ Cloud sessions terminated
☐ SaaS sessions terminated
☐ SSH sessions terminated
☐ Remote desktop sessions terminated
☐ API sessions/tokens invalidated
☐ Refresh tokens invalidated
Session Verification
25. Access Groups and Permissions
Review indirect access.
☐ Security groups reviewed
☐ Distribution groups reviewed
☐ Application groups reviewed
☐ Cloud groups reviewed
☐ Database roles reviewed
☐ Repository teams reviewed
☐ Shared-drive permissions reviewed
☐ File-sharing permissions reviewed
☐ Administrative groups reviewed
26. Delegated and Shared Access
Review access granted indirectly through:
☐ Delegation
☐ Shared mailbox
☐ Shared drive
☐ Shared account
☐ Service account
☐ Team account
☐ Application role
☐ Group membership
☐ API integration
Shared Access Action
27. Service Accounts
Determine whether the employee created or controlled service accounts.
☐ Service accounts identified
☐ Ownership reviewed
☐ Passwords/credentials reviewed
☐ API keys reviewed
☐ Access ownership transferred
☐ Credentials rotated where required
☐ Unnecessary service accounts disabled
28. Access Related to Security Tools
Review access to:
☐ SIEM
☐ EDR
☐ Vulnerability scanner
☐ Firewall
☐ WAF
☐ IAM platform
☐ Cloud security platform
☐ Monitoring platform
☐ Incident-management platform
☐ Security ticketing system
☐ Backup platform
Privileged security-tool access should receive particular attention.
29. Information Ownership
Access revocation should not accidentally disrupt business operations.
Before removing access:
☐ Business files transferred
☐ Project ownership transferred
☐ Repository ownership transferred
☐ Customer ownership transferred
☐ Supplier ownership transferred
☐ System ownership transferred
☐ Critical documentation transferred
☐ Shared resources reassigned
30. Security Incident Considerations
If revocation is related to a suspected compromise or security incident:
☐ Incident declared where appropriate
☐ Incident owner notified
☐ Evidence preservation considered
☐ Logs preserved
☐ Active sessions terminated
☐ Credentials revoked
☐ Tokens revoked
☐ Secrets rotated
☐ Relevant systems monitored
☐ Investigation requirements considered
Do not destroy evidence required for investigation merely because access is being revoked.
31. Emergency Access Revocation
For urgent situations:
☐ Emergency authorization obtained
☐ Identity disabled immediately
☐ Privileged access removed
☐ Cloud access removed
☐ Production access removed
☐ VPN removed
☐ Active sessions terminated
☐ Tokens revoked
☐ Secrets rotated where required
☐ Security team notified
☐ Incident record created where appropriate
☐ Detailed review completed after containment
32. Final Verification
A second person should verify critical revocations where practical.
☐ Corporate identity disabled
☐ Email disabled
☐ VPN removed
☐ MFA addressed
☐ AWS/cloud access removed
☐ Source-code access removed
☐ CI/CD access removed
☐ Production access removed
☐ Database access removed
☐ SaaS access removed
☐ Privileged access removed
☐ Physical access removed
☐ Tokens/keys addressed
☐ Shared credentials addressed
Verified By: __________________________
Verification Date: ____________________
Result: ☐ Complete ☐ Exceptions
33. Revocation Testing
Where appropriate, test that revoked access can no longer be used.
☐ Login attempt tested
☐ VPN access tested
☐ Cloud access tested
☐ SaaS access tested
☐ Repository access tested
☐ Production access tested
☐ Physical access tested where appropriate
Testing should be performed carefully to avoid unnecessary security events or account lockouts.
34. Exceptions
Document incomplete or delayed revocations.
| Exception | Reason | Risk | Compensating Control | Owner | Due Date | Status |
|---|---|---|---|---|---|---|
Exceptions should be formally approved according to the organization’s risk-management process.
35. Revocation Evidence
Retain appropriate evidence such as:
☐ Access-removal logs
☐ IAM evidence
☐ SaaS deactivation evidence
☐ VPN revocation evidence
☐ Repository access-removal evidence
☐ Privileged-access removal evidence
☐ Physical-access removal evidence
☐ Credential-rotation evidence
☐ Verification record
☐ Approved exception
☐ Incident record where applicable
Do not retain actual credentials or secrets as evidence.
36. Revocation Register
| Revocation ID | User | Trigger | Date/Time | Risk | Systems | Verified | Status |
|---|---|---|---|---|---|---|---|
| ☐ | |||||||
| ☐ |
37. Completion Criteria
Access revocation should not be marked Complete until:
☐ Revocation was authorized
☐ All relevant systems were identified
☐ Corporate identity was addressed
☐ Cloud access was removed
☐ SaaS access was removed
☐ VPN/remote access was removed
☐ Source-code access was removed
☐ Production access was removed
☐ Database access was removed
☐ Privileged access was removed
☐ Tokens and keys were addressed
☐ Shared credentials were reviewed
☐ Physical access was removed
☐ Delegated/group access was reviewed
☐ Business ownership was transferred
☐ Active sessions were addressed
☐ Required testing/verification was completed
☐ Exceptions were documented
☐ Evidence was retained
38. Final Approval
User/Account: ______________________________
Revocation Trigger: ______________________________
Requested By: ______________________________
Approved By: ______________________________
IT Owner: ______________________________
Security Reviewer: ______________________________
Revocation Date/Time: ______________________________
Verification Date/Time: ______________________________
Status
☐ Complete
☐ Complete with Approved Exceptions
☐ Further Action Required
Comments
39. AWS SaaS Startup Example
A developer leaves a SaaS startup.
The employee has:
- AWS access
- GitHub access
- CI/CD access
- Production database access
- VPN
- Slack
- Corporate email
- Password-manager access
Revocation Sequence
1. HR/Manager → confirms termination.
2. IT → disables the corporate identity and VPN.
3. Cloud Owner → removes AWS IAM roles, permissions, access keys, and relevant authentication methods.
4. Engineering → removes GitHub and CI/CD permissions.
5. Database Owner → removes production database access.
6. Security → reviews privileged access, tokens, shared credentials, and secrets.
7. SaaS Owners → remove access from business applications.
8. Facilities → disables physical access.
9. Reviewer → independently verifies critical access removal.
Audit Trail
Authorization → Access Inventory → Identity Revocation → Cloud Revocation → Application Revocation → Credential Review → Session Termination → Verification → Evidence → Closure
40. Startup-Friendly Revocation Model
For a small startup, the process can be simplified to seven steps:
1. Identify
Determine why access must be revoked.
2. List
Check:
- Google/Microsoft account
- AWS
- GitHub
- VPN
- SaaS
- Production
- Database
- Password manager
3. Revoke
Remove access from all relevant systems.
4. Rotate
Change shared credentials, API keys, or secrets where necessary.
5. Transfer
Transfer ownership of projects, repositories, systems, and business information.
6. Verify
A second person verifies critical access removal.
7. Record
Retain evidence and close the revocation record.
41. Common Mistakes
Avoid:
- Disabling only the email account.
- Assuming SSO removal automatically removes every application.
- Forgetting AWS/cloud access.
- Forgetting GitHub/GitLab.
- Forgetting CI/CD.
- Forgetting production databases.
- Forgetting VPN access.
- Forgetting SaaS applications.
- Forgetting physical access.
- Forgetting group memberships.
- Forgetting API keys and tokens.
- Forgetting active sessions.
- Forgetting shared credentials.
- Forgetting service accounts.
- Removing access without transferring business ownership.
- Deleting accounts before preserving investigation evidence.
- Marking access as revoked without verification.
- Keeping temporary access indefinitely.
- Failing to document exceptions.
42. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Access Management Procedure | Defines the overall access lifecycle |
| Employee Offboarding Policy | Defines termination/offboarding requirements |
| Employee Role Change Checklist | Handles access changes during role changes |
| Joiner-Mover-Leaver Procedure | Manages personnel lifecycle |
| Privileged User Management Procedure | Controls privileged access |
| Cloud Access Review Checklist | Reviews cloud permissions |
| Source Code Access Review Checklist | Reviews development access |
| Access Review Procedure | Performs periodic access reviews |
| Identity and Authentication Policy | Defines authentication requirements |
| Password/Authentication Standard | Defines authentication controls |
| Supplier Offboarding Checklist | Handles third-party access removal |
| Security Incident Response Procedure | Handles emergency access revocation |
| Information Security Exception Register | Records approved deviations |
| Corrective Action Tracker | Tracks unresolved issues |
| Asset Return Procedure | Handles associated physical assets |
43. ISO 27001 Connection
Access revocation supports the organization’s management of access rights, authentication information, privileged access, information protection, personnel changes, and secure termination of access.
The Access Revocation Checklist is not itself a universally mandatory ISO 27001 form. The organization should establish appropriate access-removal processes based on:
- ISMS scope
- Risk assessment
- Information classification
- System architecture
- User roles
- Privileged access
- Cloud/SaaS environment
- Legal and regulatory requirements
- Customer requirements
- Contractual requirements
- Business needs
The organization should be able to demonstrate that access is removed when it is no longer required and that critical revocations are appropriately verified.
44. Final Audit Checklist
☐ Revocation request received
☐ Request authorized
☐ User identity verified
☐ Revocation trigger documented
☐ Revocation timing defined
☐ Access inventory completed
☐ Corporate identity disabled
☐ SSO access removed
☐ MFA addressed
☐ Email access removed
☐ VPN access removed
☐ AWS/cloud access removed
☐ Source-code access removed
☐ CI/CD access removed
☐ Production access removed
☐ Database access removed
☐ SaaS access removed
☐ Privileged access removed
☐ Group memberships removed
☐ Delegated access removed
☐ API keys addressed
☐ Tokens revoked
☐ SSH keys addressed
☐ Service accounts reviewed
☐ Shared credentials reviewed
☐ Active sessions terminated
☐ Physical access removed
☐ Customer/supplier access removed
☐ Business ownership transferred
☐ Security incident requirements considered
☐ Emergency revocation completed where applicable
☐ Final verification completed
☐ Exceptions documented
☐ Evidence retained
☐ Revocation record closed
45. Final Audit Trail
For every significant access revocation, the organization should be able to demonstrate:
Why was access revoked?
Who authorized the revocation?
When was access required to be removed?
What systems did the user have access to?
Was corporate identity disabled?
Was cloud/AWS access removed?
Was production access removed?
Was source-code access removed?
Were database and SaaS permissions removed?
Was privileged access removed?
Were groups and delegated permissions reviewed?
Were API keys, tokens, SSH keys, and credentials addressed?
Were active sessions terminated?
Was physical access removed?
Were shared credentials rotated where necessary?
Was business ownership transferred?
Was the revocation independently verified?
Were exceptions documented and approved?
What evidence proves the access was actually revoked?
Final Principle
Access revocation is not complete when an account is disabled. It is complete when all relevant direct and indirect access, privileged permissions, sessions, credentials, tokens, physical access, and security dependencies have been addressed, verified, and recorded.
