1. Purpose
The Access Revocation Evidence Register provides a centralized record of evidence demonstrating that user access has been removed, disabled, modified, or otherwise controlled when access is no longer required.
The register supports:
- Employee offboarding
- Contractor offboarding
- Role changes
- Privileged access removal
- Emergency access revocation
- Access termination following security incidents
- Periodic access reviews
- Internal audits
- ISO 27001 audits
- SOC 2 examinations
- Security investigations
Core Principle
Identify → Revoke → Evidence → Verify → Record → Close
2. Scope
This register applies to access revocation involving:
- Employees
- Contractors
- Consultants
- Interns
- Temporary workers
- Supplier personnel
- Privileged users
- Service-account owners
- Other authorized users
It may cover:
- Corporate identity
- SSO
- VPN
- Cloud platforms
- AWS
- Azure
- Google Cloud
- Production systems
- Databases
- Source-code repositories
- CI/CD
- SaaS applications
- Security tools
- Customer environments
- Physical access
- API keys
- SSH keys
- Tokens
- Certificates
- Other authentication mechanisms
3. Register Ownership
| Field | Details |
|---|---|
| Register Owner | |
| Security Owner | |
| IAM Owner | |
| Review Frequency | |
| Register Location | |
| Retention Period | |
| Last Review Date | |
| Next Review Date |
4. Access Revocation Record
Create one record for each significant access-revocation event.
| Field | Details |
|---|---|
| Revocation ID | |
| User Name | |
| User ID | |
| User Type | ☐ Employee ☐ Contractor ☐ Supplier ☐ Other |
| Department/Company | |
| Role | |
| Privileged User | ☐ Yes ☐ No |
| Revocation Trigger | |
| Effective Date | |
| Effective Time | |
| Requested By | |
| Approved By | |
| Revoked By | |
| Verified By | |
| Completion Date | |
| Overall Status |
5. Revocation Trigger
Select the reason for access revocation.
☐ Employee termination
☐ Employee resignation
☐ Contractor offboarding
☐ Contract expiry
☐ Role change
☐ Transfer
☐ Access no longer required
☐ Privileged access removal
☐ Project completion
☐ Security incident
☐ Suspected account compromise
☐ Policy violation
☐ Emergency revocation
☐ Periodic access review
☐ Other: ______________________
Trigger Evidence
Reference: ______________________________
Evidence Location: ________________________
6. Access Revocation Evidence Register
| Revocation ID | User | System | Access Type | Action | Evidence Reference | Verified By | Status |
|---|---|---|---|---|---|---|---|
Status
☐ Pending
☐ Revocation in Progress
☐ Revoked
☐ Verification Pending
☐ Exception
☐ Closed
7. Detailed Evidence Record
For important or high-risk access revocations, record the evidence in greater detail.
| Field | Details |
|---|---|
| Evidence ID | |
| Revocation ID | |
| User | |
| System/Application | |
| Environment | ☐ Production ☐ Development ☐ Test ☐ Corporate |
| Access Type | |
| Privilege Level | ☐ Standard ☐ Elevated ☐ Privileged |
| Revocation Action | |
| Action Date/Time | |
| Performed By | |
| Evidence Type | |
| Evidence Location | |
| Evidence Date | |
| Verification Method | |
| Verified By | |
| Verification Date | |
| Result | ☐ Successful ☐ Failed ☐ Exception |
| Comments |
8. Evidence Types
Acceptable evidence may include:
☐ IAM audit log
☐ Access-management system record
☐ User-account status
☐ SSO audit log
☐ Application audit log
☐ Cloud IAM record
☐ AWS CloudTrail evidence
☐ Azure audit log
☐ Google Cloud audit log
☐ VPN access record
☐ GitHub/GitLab/Bitbucket audit log
☐ Database access record
☐ CI/CD access record
☐ SaaS audit log
☐ Security-tool audit log
☐ Physical-access record
☐ Ticket/change record
☐ Access-review record
☐ Screenshot
☐ System-generated report
☐ Email confirmation
☐ Supplier confirmation
☐ Other: ______________________
System-generated evidence should generally be preferred over manually created screenshots where reliable audit logs are available.
9. Corporate Identity Evidence
Record evidence for the organization’s primary identity system.
☐ User disabled
☐ User deleted where appropriate
☐ Group membership removed
☐ Privileged role removed
☐ SSO access removed
☐ Active sessions terminated
☐ MFA methods revoked
☐ Recovery methods removed
☐ Authentication tokens revoked
Evidence
Evidence ID: ______________________
System: ___________________________
Timestamp: ________________________
Evidence Location: _________________
10. AWS Access Revocation Evidence
Where AWS access is involved, record evidence such as:
☐ IAM Identity Center assignment removed
☐ IAM role removed
☐ IAM group membership removed
☐ IAM user disabled/deleted
☐ Access key disabled/deleted
☐ Temporary credentials expired
☐ Cross-account role access removed
☐ Administrator role removed
☐ MFA/authentication method addressed
☐ Active session addressed
☐ CloudTrail activity reviewed where required
AWS Evidence
| AWS Account | Role/Permission | Action | Evidence ID | Verified |
|---|---|---|---|---|
Evidence Reference
CloudTrail/Event Reference: __________________________
IAM Evidence: ______________________________________
Verification: _______________________________________
11. Azure Access Evidence
Where Azure is involved:
☐ User disabled
☐ Entra ID roles removed
☐ Subscription roles removed
☐ Resource-group roles removed
☐ Privileged Identity Management access removed
☐ Sessions/tokens addressed
☐ MFA/authentication methods addressed
Evidence
Evidence ID: ______________________
Audit Log Reference: ______________
Verification: _____________________
12. Google Cloud Access Evidence
Where Google Cloud is involved:
☐ User access removed
☐ IAM roles removed
☐ Project permissions removed
☐ Organization permissions removed
☐ Service-account relationships reviewed
☐ Credentials revoked where required
Evidence
Evidence ID: ______________________
Audit Log Reference: ______________
Verification: _____________________
13. Production Access Evidence
For production access:
| System | User | Privilege | Revocation Action | Evidence | Verified |
|---|---|---|---|---|---|
Evidence may include:
- IAM logs
- Kubernetes audit logs
- SSH access records
- VPN records
- Production console audit logs
- Database access logs
- PAM records
- Change-management records
14. Source-Code Access Evidence
Record evidence for:
☐ GitHub
☐ GitLab
☐ Bitbucket
☐ Azure DevOps
☐ Other repository
Verify:
☐ Repository access removed
☐ Organization role removed
☐ SSH key revoked
☐ Personal access token revoked
☐ OAuth authorization revoked
☐ Deployment access removed
☐ Administrative role removed
Evidence
| Platform | Repository/Organization | Action | Evidence | Verified |
|---|---|---|---|---|
15. Database Access Evidence
Where database access is involved:
☐ User disabled
☐ Database role removed
☐ Administrative privilege removed
☐ Database credentials revoked
☐ Shared credentials rotated where required
☐ Connection access removed
Evidence
Database: ______________________________
User/Role: ______________________________
Action: _________________________________
Evidence Reference: _____________________
Verified By: ____________________________
16. VPN and Network Access Evidence
Verify:
☐ VPN account disabled
☐ Network group membership removed
☐ Firewall access removed
☐ Remote-access certificate revoked
☐ Network authentication removed
☐ Active sessions terminated
Evidence
System: ______________________________
Evidence Reference: ___________________
Date/Time: ____________________________
Verified By: __________________________
17. SaaS Access Evidence
Record evidence for administrative or sensitive SaaS access.
Examples:
- Microsoft 365
- Google Workspace
- Slack
- Jira
- Salesforce
- CRM
- HR systems
- Security platforms
- Monitoring platforms
| SaaS | User | Role | Action | Evidence | Verified |
|---|---|---|---|---|---|
18. API Keys, Tokens and SSH Keys
Determine whether access revocation requires credential invalidation.
☐ API keys revoked
☐ Personal access tokens revoked
☐ OAuth tokens revoked
☐ SSH keys revoked
☐ Cloud access keys revoked
☐ Certificates revoked
☐ Service credentials reviewed
☐ Shared secrets rotated
Evidence
| Credential Type | System | Action | Evidence | Verified |
|---|---|---|---|---|
Important: Never store the actual secret value in this register.
Record only the credential identifier, system, action, timestamp, and evidence reference.
19. Shared Credential Evidence
If the user knew a shared credential:
☐ Shared credential identified
☐ Risk assessed
☐ Credential rotated
☐ New credential securely distributed
☐ Old credential invalidated
☐ Vault record updated
☐ Access ownership updated
Evidence
System: ______________________________
Credential Identifier: ________________
Rotation Date: ________________________
Evidence Reference: ___________________
20. Physical Access Evidence
Where applicable:
☐ Access card disabled
☐ Building access removed
☐ Data-center access removed
☐ Restricted-area access removed
☐ Keys recovered
☐ Biometric access removed
Evidence
Access System: _______________________
Record ID: ___________________________
Date/Time: ___________________________
21. Verification Evidence
Access revocation should be verified according to the risk of the access.
Verification Methods
☐ Audit-log review
☐ Account-status review
☐ Role-assignment review
☐ Controlled login test
☐ Access-attempt validation
☐ System-owner confirmation
☐ IAM confirmation
☐ Cloud administrator confirmation
☐ Supplier confirmation
☐ Other: ______________________
Verification Record
| Revocation ID | Verification Method | Verified By | Date | Result |
|---|---|---|---|---|
22. Independent Verification
For high-risk or privileged access, independent verification should be performed where practical.
☐ Required
☐ Not Required
Independent Reviewer
Name: ______________________________
Role: _______________________________
Date: _______________________________
Result: ☐ Successful ☐ Exception
Reviewer Comments
23. Evidence Integrity
Where evidence is important to an investigation, audit, or legal matter, consider recording:
- Evidence source
- Evidence creation date/time
- Evidence collection date/time
- Collector
- Original system
- Evidence location
- File name/reference
- Hash/checksum where appropriate
- Chain-of-custody reference where required
Evidence Integrity Record
| Evidence ID | Source | Collected By | Collection Date | Integrity Method | Reference |
|---|---|---|---|---|---|
Routine access-revocation evidence does not necessarily require forensic chain-of-custody procedures unless the evidence is being preserved for an investigation or legal matter.
24. Evidence Repository
Record where supporting evidence is stored.
| Evidence ID | Evidence Type | Repository | Path/Reference | Access Restricted |
|---|---|---|---|---|
Evidence repositories should have appropriate access restrictions and retention controls.
25. Evidence Retention
Retain access-revocation evidence according to:
- Organizational retention requirements
- Audit requirements
- Contractual requirements
- Legal requirements
- Regulatory requirements
- Security investigation requirements
Retention
Retention Period: __________________________
Review/Deletion Date: ______________________
Evidence should not be retained indefinitely without a legitimate business, legal, regulatory, or audit requirement.
26. Exceptions
Record any access that could not be revoked as planned.
| Revocation ID | System | Access | Reason | Risk | Temporary Control | Owner | Due Date |
|---|---|---|---|---|---|---|---|
Examples:
- System unavailable
- Third-party dependency
- Service account dependency
- Emergency operational requirement
- Technical limitation
Exceptions should be tracked until closure.
27. Failed Revocation
If access revocation fails:
☐ Failure identified
☐ Security notified
☐ System owner notified
☐ Risk assessed
☐ Temporary control implemented
☐ Credential/session addressed
☐ Root cause investigated
☐ Successful revocation confirmed
☐ Evidence updated
Failure Details
28. Emergency Revocation Evidence
For emergency access revocation:
Reason: ______________________________
Requested By: ________________________
Effective Time: _______________________
Action Taken: _________________________
System: ______________________________
Evidence Reference: ___________________
Verified By: __________________________
Verification Time: ____________________
Follow-Up Review Required: ☐ Yes ☐ No
Emergency revocation should be documented even when normal approval steps cannot be completed before the access is removed.
29. Evidence Quality Check
Before closing the record, verify:
☐ Evidence identifies the correct user
☐ Evidence identifies the correct system
☐ Evidence demonstrates the required action
☐ Date/time is available
☐ Evidence source is known
☐ Evidence has not been unnecessarily altered
☐ Evidence can be retrieved
☐ Evidence is access-controlled
☐ Evidence retention requirement is known
☐ Independent verification completed where required
30. Final Revocation Record
Revocation ID: ______________________________
User: ______________________________________
Reason: ____________________________________
Effective Date/Time: _________________________
Systems Covered: ____________________________
Privileged Access: ☐ Yes ☐ No
Production Access: ☐ Yes ☐ No
Cloud Access: ☐ Yes ☐ No
Customer Access: ☐ Yes ☐ No
All Required Access Revoked: ☐ Yes ☐ No
Exceptions: ☐ None ☐ Documented
Evidence Complete: ☐ Yes ☐ No
Independent Verification: ☐ Completed ☐ Not Required
Final Status: ☐ Closed ☐ Open
31. Final Approval
Person Performing Revocation
Name: ______________________________
Role: _______________________________
Date: _______________________________
Signature/Approval: __________________
Reviewer
Name: ______________________________
Role: _______________________________
Date: _______________________________
Signature/Approval: __________________
Security/Business Owner
Name: ______________________________
Date: _______________________________
Approval: ____________________________
32. AWS SaaS Startup Example
A SaaS startup terminates a DevOps contractor who has:
- AWS access
- Production Kubernetes access
- GitHub access
- CI/CD access
- Production database access
- VPN access
Evidence Register
| System | Action | Evidence |
|---|---|---|
| AWS IAM Identity Center | Assignment removed | IAM audit record |
| AWS IAM | Privileged roles removed | IAM audit record |
| GitHub | Organization access removed | GitHub audit log |
| SSH | Key revoked | Access-management record |
| Kubernetes | Admin role removed | Kubernetes audit log |
| Database | User/role disabled | Database audit record |
| CI/CD | Deployment access removed | CI/CD audit log |
| VPN | Account disabled | VPN audit log |
Verification
The security reviewer checks:
- Contractor account is disabled.
- AWS privileged roles are no longer assigned.
- GitHub organization access is removed.
- Production Kubernetes permissions are removed.
- Database access is removed.
- VPN access is disabled.
- Shared production credentials known to the contractor have been rotated.
The reviewer records the evidence references and closes the revocation record.
Audit Trail
Offboarding Request → Access Inventory → Revocation → Evidence Collection → Independent Verification → Exception Review → Closure
33. Startup-Friendly Model
A startup does not need a complicated evidence system.
For each significant access revocation, retain at least:
1. Who — User and role
2. Why — Termination, role change, contract end, etc.
3. What — Systems and access removed
4. When — Revocation date/time
5. How — Method used to revoke access
6. Evidence — System-generated record or audit log
7. Who verified — Reviewer
8. Exceptions — Anything not completed
This creates a simple but defensible audit trail.
34. Common Mistakes
Avoid:
- Recording only that “access was removed.”
- Failing to identify the system.
- Failing to record the revocation date/time.
- Storing actual passwords or API keys as evidence.
- Relying only on screenshots when reliable audit logs exist.
- Forgetting cloud access.
- Forgetting privileged roles.
- Forgetting API keys and tokens.
- Forgetting active sessions.
- Failing to verify revocation.
- Allowing exceptions without owners.
- Keeping sensitive evidence in unrestricted folders.
- Deleting evidence immediately after the access change.
- Retaining evidence indefinitely without a defined requirement.
35. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Access Revocation Checklist | Defines access-removal activities |
| Access Management Procedure | Defines access lifecycle |
| Privileged User Offboarding Checklist | Covers privileged access removal |
| Employee Offboarding Policy | Covers employee exit |
| Contractor Offboarding Procedure | Covers contractor exit |
| Exit Security Acknowledgement | Records individual security acknowledgement |
| Access Review Procedure | Reviews ongoing access |
| IAM Procedure | Defines identity and access management |
| Incident Response Procedure | Supports emergency access revocation |
| Evidence Preservation Procedure | Handles investigation evidence |
| Asset Return Checklist | Handles company assets |
| Access Register | Records authorized access |
36. ISO 27001 / SOC 2 Connection
The Access Revocation Evidence Register provides supporting evidence that access is removed or adjusted when it is no longer required and that access-control activities are documented and reviewable.
It can support evidence for areas including:
- Identity management
- Access control
- Privileged access
- Authentication
- Personnel offboarding
- Supplier offboarding
- Information protection
- Security monitoring
- Incident response
For ISO 27001, the specific applicable controls and evidence should be determined through the organization’s risk assessment and Statement of Applicability.
For SOC 2, the register can provide a structured audit trail demonstrating that access termination activities occurred and were independently reviewed where required.
37. Quick Audit Checklist
☐ User identified
☐ Revocation trigger documented
☐ Effective date/time documented
☐ Access inventory completed
☐ Corporate access revoked
☐ Cloud access revoked
☐ AWS access revoked
☐ Production access revoked
☐ Database access revoked
☐ Source-code access revoked
☐ CI/CD access revoked
☐ VPN access revoked
☐ SaaS access revoked
☐ Privileged access revoked
☐ API tokens addressed
☐ SSH keys addressed
☐ Shared credentials assessed
☐ Sessions addressed
☐ Physical access addressed
☐ Evidence reference recorded
☐ Evidence source identified
☐ Verification completed
☐ Exceptions documented
☐ Evidence retained appropriately
☐ Final approval completed
☐ Register closed
38. Final Audit Trail
For every significant access-revocation event, the organization should be able to demonstrate:
Who was the user?
Why was access revoked?
When was access required to be revoked?
What systems and privileges were affected?
What action was performed?
Who performed the action?
What evidence proves the action occurred?
Who verified the revocation?
Were privileged, cloud, production, and external accesses addressed?
Were credentials, tokens, keys, and shared secrets considered?
Were exceptions documented?
Where is the supporting evidence stored?
Who approved closure?
Final Principle
Access revocation is not complete when someone says access was removed. It is complete when the organization can demonstrate what was revoked, when it was revoked, who performed it, who verified it, and where the evidence is retained.
