Core workflows

Maintain a system register and run access reviews

List every platform, SaaS tool and supplier in scope, record who owns it and how people sign in, then evidence periodic access reviews with keep, modify or revoke decisions.

7 min read · updated July 2026

Step-by-step

  1. 1

    Open Systems & access

    The KPI strip shows total systems, how many are critical or high, how many lack enforced MFA, and how many access reviews are overdue or open.

    The system register with criticality, ownership and MFA posture.
    The system register with criticality, ownership and MFA posture.
  2. 2

    Add your systems

    Click New system and record the platform, supplier, criticality, the data it holds, the business owner and technical owner, and how users authenticate (SSO, MFA, password only).

  3. 3

    Link systems to what they touch

    Connect each system to the assets, risks and controls involved so a change of supplier or criticality ripples into your risk picture.

  4. 4

    Start an access review

    On the Access reviews tab, open a review for a system, set the period and reviewer, and list the users with access.

  5. 5

    Decide user by user

    For each user, record keep, modify or revoke with a short reason. Revocations should raise a remediation action if they can't be actioned immediately.

  6. 6

    Complete and evidence

    Complete the review to stamp it with a date and reviewer, then export the CSV for the audit file or a buyer questionnaire.

What corporate buyers look for
  • "Do you maintain an inventory of systems that process our data?"
  • "Is MFA or SSO enforced on all business-critical systems?"
  • "How frequently do you review user access, and can you show the last review?"

What this workflow produces: A system register plus a completed access review showing per-user decisions — one of the most common gaps found in supplier assurance and ISO 27001 stage 2 audits.

FAQ

How often should access be reviewed?

Quarterly for critical systems, at least annually for everything else, and immediately on leaver events.

Do I need every internal tool in the register?

Include anything that processes business or customer data, or that could affect availability. Trivial tools with no data can be excluded — document why.

How does this relate to the asset inventory?

Assets are the information and equipment; systems are the platforms that process them. They link to each other rather than duplicate.

Ready to run this in your workspace?

Start free — the workspace comes pre-loaded with the frameworks, policies and templates you need to follow this guide today.

Related

ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation