Skip to content

Access control register

Planning aid, not a certification or legally sufficient compliance document. Complete in an approved private documentation location. Never insert credentials, key material, or actual restricted records. Unknown required controls block approval.

  • Project / nonsensitive identifier: [fill in]
  • Prepared by / accountable owner: [fill in]
  • Version / date / next review: [fill in]
  • Classification and agreement references: [fill in]
  • Approved evidence location: [fill in]

Named access and privileges

User/group id Organization Purpose / role Systems and permissions Approval / expiry MFA/auth route Last review Removal evidence
[fill in]
  • Group memberships and review owner: [fill in]
  • CyVerse parent, collection, and object ACL evidence: [fill in]
  • Tickets, public sharing links, service accounts, and expiry: [fill in]
  • VM, cloud, storage, support and container-daemon administrators: [fill in]
  • Key release/recovery privileges, separately authorized: [fill in]
  • Access request and custodian approval process: [fill in]
  • Non-member synthetic denial test reference: [fill in]
  • Joiner/mover/leaver process and revocation timing: [fill in]
  • Emergency access and audit process: [fill in]

Review and authorization

  • Unresolved controls / remediation owner / due date: [fill in]
  • Exceptions, approving authority, scope, and expiry: [fill in]
  • Custodian decision / date / evidence reference: [fill in]
  • Institutional decision / date / evidence reference: [fill in]
  • Provider confirmation references: [fill in]
  • Material changes requiring revalidation: [fill in]

For each control, record Supported, Configured, Verified, and Approved separately, with dates and evidence. Do not mark unknown as passed.