B BROCENT
Brocent — Your Asia IT Team
BCS Support Center · Hong Kong
it-service@brocent.com
Quarterly client report · 07 of 09

Access & Permission Review

Entitlement certification across file shares, Microsoft 365 sites, applications and privileged roles, with separation-of-duties testing and revocation evidence for the third quarter of 2026.

Client
Acme Capital Limited
Reporting period
2026-07-01 → 09-30
Issued
2026-09-03
Reference
ACR-2026-Q3
Scope
8 systems · 41 staff · 9 guests
Entitlements
386 reviewed
Prepared by
BCS Support Center
Classification
Confidential
01 · Executive summary

The review is complete and evidenced; accumulated access from role changes is the theme

All 386 entitlements across eight systems were certified by a named business approver within the quarter, giving 100% review completion for the second consecutive cycle. Twenty-three entitlements were revoked as a result, twenty-one of them access that staff had retained after a role change rather than access that was wrongly granted.

Two control weaknesses were identified. One separation-of-duties conflict remains open: the same person can both create a payment instruction and approve it in the accounting application, mitigated today only by a manual four-eyes convention with no system enforcement. Second, the investor-relations SharePoint site grants edit rights to eleven staff where six would be sufficient, because permission is inherited from a broad group rather than granted by role.

Service verdict
Met, with action
Four of five review service levels were met; two revocations exceeded the five-day action target. The separation-of-duties conflict and the over-broad site permissions are tracked as ACR-R01 and ACR-R02.
02 · Key indicators

Review position at quarter end

Review completion
100%
— 386 of 386
Entitlements revoked
23
▲ +9 vs Q2
SoD conflicts open
1
▲ −1 vs Q2
Over-broad grants
5
— 1 site, 4 shares
Privileged roles
5
▲ all justified
Exceptions granted
2
— both time-limited
Mean revocation time
3.1 d
▼ 2 over 5-day target
Orphaned entitlements
0
▲ −3 vs Q2

An entitlement is one identity's access to one resource at one permission level. The same person's read access to two shares is two entitlements, which is why the total exceeds the account count several times over.

03 · Key findings

Four items require action

One person can both create and approve a payment instruction · carried forward (2 periods)
CRITICAL

Evidence. The finance manager holds both the payment-preparer and payment-approver roles in the accounting application. The application supports role separation but both roles are assigned to the same identity. The compensating control is a manual convention that a second person reviews the bank file before release, with no system record of that review.

Impact. A single individual can originate and release a payment without an enforced second pair of eyes, and the firm cannot evidence to an auditor or investor that a second review occurred. This is the highest-consequence finding in the access domain.

Recommendation. Remove the approver role from the preparer identity and assign it to the COO, with a named delegate for absence. Where the application cannot enforce this, move payment release to the bank portal's own dual-authorisation and record the arrangement in the finance procedure.

Owner Client COO Target 2026-09-30 Ref ACR-2026-Q2-01
Eleven staff hold edit rights to the investor-relations site
HIGH

Evidence. Edit permission is inherited from the "All Staff" group rather than granted by role. Six people work on investor material; the other five have no business need. The site also holds four of the anonymous sharing links reported in the M365 Security report.

Impact. Broad edit rights on investor material raise both the accidental-change risk and the blast radius of a single compromised account. Inheritance also means new joiners receive the access automatically.

Recommendation. Break inheritance, create an investor-relations role group with the six required members, and set the remaining staff to no access rather than read.

Owner BCS Support Center Target 2026-09-30 Ref ACR-2026-Q3-02
Four file shares grant access through nested groups that no one can explain
MEDIUM

Evidence. Four shares on the file server derive their access from groups nested up to three levels deep, including two groups created before 2023 with names that no longer match any current team. Effective access had to be computed rather than read, and two approvers could not confirm intent without investigation.

Impact. Where access cannot be read directly it cannot be reviewed meaningfully. Certification becomes a formality, which is worse than no review because it creates false assurance.

Recommendation. Flatten to a single group per share per permission level, retire the two legacy groups, and re-certify the four shares out of cycle once flattened.

Owner BCS Support Center Target 2026-11-30 Ref ACR-2026-Q3-03
Two revocations took longer than the five-day target
LOW

Evidence. Two market-data terminal entitlements took nine and eleven days to remove because the change requires a vendor ticket rather than a local administrative action.

Recommendation. Agree a vendor service level for entitlement changes, or accept a documented ten-day target for vendor-controlled systems so the measure reflects reality.

Owner BCS + Client IT Target 2026-12-31 Ref ACR-2026-Q3-04
Closed this quarter · three orphaned entitlements and one SoD conflict removed
RESOLVED

The three entitlements belonging to departed staff identified in Q2 were removed on 2026-07-14. The Q2 conflict where an operations user could both amend and release a trade confirmation was resolved by moving release to the front-office desk head on 2026-08-05.

04 · Service level attainment

Four of five service levels met

Committed service levelTargetActualStatusNote
Review completed in quarter 100% 100% MET 386 entitlements, 8 systems
Named approver per system 8 of 8 8 of 8 MET All attestations signed
Revocation actioned ≤ 5 days 3.1 d avg MISSED 2 of 23 exceeded (vendor system)
Privileged role justification 100% 100% MET 5 roles, all re-justified
Report issued after quarter close ≤ 10 working days 3rd working day MET Interim issue; final at 09-30
05 · Trend

Three-period movement

MetricQ1 2026Q2 2026Q3 2026Direction of travel
Entitlements in scope 402 394 386 Falling as accumulated access is removed.
Review completion 78% 100% 100% Sustained after the Q1 process change.
Entitlements revoked 8 14 23 Rising because the review is now genuinely challenging access.
SoD conflicts open 3 2 1 One closed per quarter; the payment conflict is the hardest.
Orphaned entitlements 7 3 0 Eliminated; leaver process now removes entitlements directly.
Mean revocation time 6.8 d 4.2 d 3.1 d Improving; residual delay is vendor-controlled systems.
Review outcome · 386 entitlements
Confirmed as appropriate · 353 Reduced permission level · 10 Revoked · 23

Twenty-one of the 23 revocations were access retained after a role change, which is why the mover step in the joiner-mover-leaver process is the highest-value place to intervene.

06 · Detail data

Review coverage by system

SystemApprover roleEntitlementsConfirmedReducedRevokedCertifiedNote
File server sharesClient IT lead118104592026-08-124 shares need flattening
SharePoint sitesSite owners9688352026-08-14Investor site over-broad
Microsoft 365 groupsOps lead6461032026-08-143 dormant guests removed
Accounting applicationClient COO3129112026-08-19SoD conflict open
Market-data terminalFront-office head3431122026-08-21Vendor-controlled changes
VPN and remote accessClient IT lead2221012026-08-12Contractor access closed
Privileged roles (tenant)Client COO55002026-08-19All re-justified
Network device adminBCS service manager1614022026-08-26Shared accounts to be replaced

Totals: 386 entitlements, 353 confirmed, 10 reduced, 23 revoked. Each certification is evidenced by a signed attestation held in the service record and available for inspection.

Separation-of-duties testing

Conflict testedResultDetail
Create and approve paymentCONFLICTFinance manager holds both roles; manual four-eyes convention only. Open finding.
Amend and release trade confirmationCLEARResolved 2026-08-05; release now sits with the desk head.
Create user and grant privilegeCLEARBCS creates accounts; privilege assignment requires client COO approval.
Administer backup and delete dataPARTIALMitigated for one set by immutability; two sets still deletable — see Backup report BKUP-R01.
Approve own access requestCLEARWorkflow blocks self-approval; two attempts correctly rejected in the quarter.

Access exceptions

ExceptionGrantedExpiresApproverJustification
Temporary finance read access2026-08-042026-09-30Client COOAudit preparation support by the operations lead.
Contractor VPN reinstatement2026-08-182026-10-31Client IT leadFixed-scope research project; access limited to one share.

Every exception carries an expiry date at grant time. An exception without an expiry is treated as a finding, not an exception.

07 · Risk register

Open items carried between quarters

RefRiskSeverityOwnerDueStatusNext action
ACR-R01 Payment creation and approval in one identity — no enforced four-eyes CRITICAL Client COO 2026-09-30 Open Reassign the approver role or move release to bank dual-authorisation.
ACR-R02 Over-broad edit rights on investor material — inherited from All Staff HIGH BCS Support Center 2026-09-30 Open Break inheritance; create a six-member role group.
ACR-R03 Nested group sprawl on four shares — access cannot be read directly MEDIUM BCS Support Center 2026-11-30 Open Flatten to one group per share per level; re-certify out of cycle.
ACR-R04 Shared network device administrator accounts — actions unattributable MEDIUM BCS Support Center 2026-10-31 In progress Move to identity-backed named accounts — see CONF-R01.
ACR-R05 No vendor service level for entitlement changes — revocation target unachievable LOW BCS + Client IT 2026-12-31 Open Agree a vendor target or document a 10-day target for those systems.

Next period commitments

BCS Support Center willClient is asked to
Break inheritance on the investor site and build the role group. Reassign the payment approver role away from the preparer.
Flatten the four nested-group shares and re-certify them out of cycle. Confirm the six staff who require investor-material edit rights.
Replace shared network device credentials with named accounts. Confirm whether the two access exceptions expire as scheduled.
Issue the final Q3 report after the 2026-09-30 close. Nominate approvers for the Q4 review cycle by 2026-10-07.
Appendix · Method and definitions

How this report was produced

SourceExtractedRecordsUsed for
File share ACL export 2026-08-10 21:00 HKT 118 entitlements Effective access per identity per share, with group resolution.
SharePoint permission report 2026-08-12 21:00 HKT 96 entitlements Site and library permissions, inheritance state.
Entra ID groups and roles 2026-08-12 21:10 HKT 69 entitlements Group membership, guest access, privileged role assignment.
Application role exports 2026-08-18 65 entitlements Accounting and market-data roles for SoD testing.
Attestation records 2026-08-26 8 attestations Approver identity, decision, date and comments.
HR roster 2026-08-29 41 staff Role validation and mover detection.

Method and definitions

Entitlement is one identity's access to one resource at one permission level. Access granted through a group is attributed to the individual, not the group, so the review challenges effective access rather than nominal membership.

Certification requires a named business approver — never BCS alone — to record a decision of confirm, reduce or revoke against each entitlement. An entitlement with no recorded decision counts as incomplete, not as confirmed.

Separation-of-duties conflict is tested against a fixed matrix of five incompatible role pairs agreed with the client. A conflict mitigated only by manual convention is reported as a conflict, because it cannot be evidenced after the fact.

Exclusions. Account existence and MFA state are reported monthly in the Account Management report. Tenant-level sharing configuration is reported in the M365 Security report. Physical access to the offices is outside the managed service.

Anonymisation notice

This copy is an anonymised sample prepared for illustration. The client name, system names, role titles, share names and approver identities have been replaced with fictitious or generic values; counts, ratios, dates and findings reflect a representative managed estate. No real client data appears in this document.

Questions on this report
BCS Support Center · it-service@brocent.com
Brocent — Your Asia IT Team
Frequently asked

Questions clients ask about this report

What is an entitlement review and who signs it off?

Every identity's access to every resource at every permission level is presented to a named business approver, who records confirm, reduce or revoke. Brocent never certifies access on the client's behalf — an entitlement with no recorded business decision counts as incomplete, not as confirmed.

How do you test separation of duties?

Against a fixed matrix of incompatible role pairs agreed with the client — for example creating and approving a payment. A conflict mitigated only by a manual convention is still reported as a conflict, because it cannot be evidenced after the fact.

How often should a regulated Hong Kong firm review access?

Quarterly for entitlements and privileged roles is the position most investor due-diligence questionnaires expect, with removal on the day of departure handled by the monthly account process rather than waiting for the review.

Next step

See what your own Access & Permission Review report would say

A free IT health check produces a first version of this report against your real estate, at no cost and with no obligation. It takes about a week and needs a few hours of your team's time.

Book a free IT health check Contact BCS Support Center