it-service@brocent.com
Access & Permission Review
Entitlement certification across file shares, Microsoft 365 sites, applications and privileged roles, with separation-of-duties testing and revocation evidence for the third quarter of 2026.
The review is complete and evidenced; accumulated access from role changes is the theme
All 386 entitlements across eight systems were certified by a named business approver within the quarter, giving 100% review completion for the second consecutive cycle. Twenty-three entitlements were revoked as a result, twenty-one of them access that staff had retained after a role change rather than access that was wrongly granted.
Two control weaknesses were identified. One separation-of-duties conflict remains open: the same person can both create a payment instruction and approve it in the accounting application, mitigated today only by a manual four-eyes convention with no system enforcement. Second, the investor-relations SharePoint site grants edit rights to eleven staff where six would be sufficient, because permission is inherited from a broad group rather than granted by role.
Review position at quarter end
An entitlement is one identity's access to one resource at one permission level. The same person's read access to two shares is two entitlements, which is why the total exceeds the account count several times over.
Four items require action
Evidence. The finance manager holds both the payment-preparer and payment-approver roles in the accounting application. The application supports role separation but both roles are assigned to the same identity. The compensating control is a manual convention that a second person reviews the bank file before release, with no system record of that review.
Impact. A single individual can originate and release a payment without an enforced second pair of eyes, and the firm cannot evidence to an auditor or investor that a second review occurred. This is the highest-consequence finding in the access domain.
Recommendation. Remove the approver role from the preparer identity and assign it to the COO, with a named delegate for absence. Where the application cannot enforce this, move payment release to the bank portal's own dual-authorisation and record the arrangement in the finance procedure.
Evidence. Edit permission is inherited from the "All Staff" group rather than granted by role. Six people work on investor material; the other five have no business need. The site also holds four of the anonymous sharing links reported in the M365 Security report.
Impact. Broad edit rights on investor material raise both the accidental-change risk and the blast radius of a single compromised account. Inheritance also means new joiners receive the access automatically.
Recommendation. Break inheritance, create an investor-relations role group with the six required members, and set the remaining staff to no access rather than read.
Evidence. Four shares on the file server derive their access from groups nested up to three levels deep, including two groups created before 2023 with names that no longer match any current team. Effective access had to be computed rather than read, and two approvers could not confirm intent without investigation.
Impact. Where access cannot be read directly it cannot be reviewed meaningfully. Certification becomes a formality, which is worse than no review because it creates false assurance.
Recommendation. Flatten to a single group per share per permission level, retire the two legacy groups, and re-certify the four shares out of cycle once flattened.
Evidence. Two market-data terminal entitlements took nine and eleven days to remove because the change requires a vendor ticket rather than a local administrative action.
Recommendation. Agree a vendor service level for entitlement changes, or accept a documented ten-day target for vendor-controlled systems so the measure reflects reality.
The three entitlements belonging to departed staff identified in Q2 were removed on 2026-07-14. The Q2 conflict where an operations user could both amend and release a trade confirmation was resolved by moving release to the front-office desk head on 2026-08-05.
Four of five service levels met
| Committed service level | Target | Actual | Status | Note |
|---|---|---|---|---|
| Review completed in quarter | 100% | 100% | MET | 386 entitlements, 8 systems |
| Named approver per system | 8 of 8 | 8 of 8 | MET | All attestations signed |
| Revocation actioned | ≤ 5 days | 3.1 d avg | MISSED | 2 of 23 exceeded (vendor system) |
| Privileged role justification | 100% | 100% | MET | 5 roles, all re-justified |
| Report issued after quarter close | ≤ 10 working days | 3rd working day | MET | Interim issue; final at 09-30 |
Three-period movement
| Metric | Q1 2026 | Q2 2026 | Q3 2026 | Direction of travel |
|---|---|---|---|---|
| Entitlements in scope | 402 | 394 | 386 | Falling as accumulated access is removed. |
| Review completion | 78% | 100% | 100% | Sustained after the Q1 process change. |
| Entitlements revoked | 8 | 14 | 23 | Rising because the review is now genuinely challenging access. |
| SoD conflicts open | 3 | 2 | 1 | One closed per quarter; the payment conflict is the hardest. |
| Orphaned entitlements | 7 | 3 | 0 | Eliminated; leaver process now removes entitlements directly. |
| Mean revocation time | 6.8 d | 4.2 d | 3.1 d | Improving; residual delay is vendor-controlled systems. |
Twenty-one of the 23 revocations were access retained after a role change, which is why the mover step in the joiner-mover-leaver process is the highest-value place to intervene.
Review coverage by system
| System | Approver role | Entitlements | Confirmed | Reduced | Revoked | Certified | Note |
|---|---|---|---|---|---|---|---|
| File server shares | Client IT lead | 118 | 104 | 5 | 9 | 2026-08-12 | 4 shares need flattening |
| SharePoint sites | Site owners | 96 | 88 | 3 | 5 | 2026-08-14 | Investor site over-broad |
| Microsoft 365 groups | Ops lead | 64 | 61 | 0 | 3 | 2026-08-14 | 3 dormant guests removed |
| Accounting application | Client COO | 31 | 29 | 1 | 1 | 2026-08-19 | SoD conflict open |
| Market-data terminal | Front-office head | 34 | 31 | 1 | 2 | 2026-08-21 | Vendor-controlled changes |
| VPN and remote access | Client IT lead | 22 | 21 | 0 | 1 | 2026-08-12 | Contractor access closed |
| Privileged roles (tenant) | Client COO | 5 | 5 | 0 | 0 | 2026-08-19 | All re-justified |
| Network device admin | BCS service manager | 16 | 14 | 0 | 2 | 2026-08-26 | Shared accounts to be replaced |
Totals: 386 entitlements, 353 confirmed, 10 reduced, 23 revoked. Each certification is evidenced by a signed attestation held in the service record and available for inspection.
Separation-of-duties testing
| Conflict tested | Result | Detail |
|---|---|---|
| Create and approve payment | CONFLICT | Finance manager holds both roles; manual four-eyes convention only. Open finding. |
| Amend and release trade confirmation | CLEAR | Resolved 2026-08-05; release now sits with the desk head. |
| Create user and grant privilege | CLEAR | BCS creates accounts; privilege assignment requires client COO approval. |
| Administer backup and delete data | PARTIAL | Mitigated for one set by immutability; two sets still deletable — see Backup report BKUP-R01. |
| Approve own access request | CLEAR | Workflow blocks self-approval; two attempts correctly rejected in the quarter. |
Access exceptions
| Exception | Granted | Expires | Approver | Justification |
|---|---|---|---|---|
| Temporary finance read access | 2026-08-04 | 2026-09-30 | Client COO | Audit preparation support by the operations lead. |
| Contractor VPN reinstatement | 2026-08-18 | 2026-10-31 | Client IT lead | Fixed-scope research project; access limited to one share. |
Every exception carries an expiry date at grant time. An exception without an expiry is treated as a finding, not an exception.
Open items carried between quarters
| Ref | Risk | Severity | Owner | Due | Status | Next action |
|---|---|---|---|---|---|---|
| ACR-R01 | Payment creation and approval in one identity — no enforced four-eyes | CRITICAL | Client COO | 2026-09-30 | Open | Reassign the approver role or move release to bank dual-authorisation. |
| ACR-R02 | Over-broad edit rights on investor material — inherited from All Staff | HIGH | BCS Support Center | 2026-09-30 | Open | Break inheritance; create a six-member role group. |
| ACR-R03 | Nested group sprawl on four shares — access cannot be read directly | MEDIUM | BCS Support Center | 2026-11-30 | Open | Flatten to one group per share per level; re-certify out of cycle. |
| ACR-R04 | Shared network device administrator accounts — actions unattributable | MEDIUM | BCS Support Center | 2026-10-31 | In progress | Move to identity-backed named accounts — see CONF-R01. |
| ACR-R05 | No vendor service level for entitlement changes — revocation target unachievable | LOW | BCS + Client IT | 2026-12-31 | Open | Agree a vendor target or document a 10-day target for those systems. |
Next period commitments
| BCS Support Center will | Client is asked to |
|---|---|
| Break inheritance on the investor site and build the role group. | Reassign the payment approver role away from the preparer. |
| Flatten the four nested-group shares and re-certify them out of cycle. | Confirm the six staff who require investor-material edit rights. |
| Replace shared network device credentials with named accounts. | Confirm whether the two access exceptions expire as scheduled. |
| Issue the final Q3 report after the 2026-09-30 close. | Nominate approvers for the Q4 review cycle by 2026-10-07. |
How this report was produced
| Source | Extracted | Records | Used for |
|---|---|---|---|
| File share ACL export | 2026-08-10 21:00 HKT | 118 entitlements | Effective access per identity per share, with group resolution. |
| SharePoint permission report | 2026-08-12 21:00 HKT | 96 entitlements | Site and library permissions, inheritance state. |
| Entra ID groups and roles | 2026-08-12 21:10 HKT | 69 entitlements | Group membership, guest access, privileged role assignment. |
| Application role exports | 2026-08-18 | 65 entitlements | Accounting and market-data roles for SoD testing. |
| Attestation records | 2026-08-26 | 8 attestations | Approver identity, decision, date and comments. |
| HR roster | 2026-08-29 | 41 staff | Role validation and mover detection. |
Method and definitions
Entitlement is one identity's access to one resource at one permission level. Access granted through a group is attributed to the individual, not the group, so the review challenges effective access rather than nominal membership.
Certification requires a named business approver — never BCS alone — to record a decision of confirm, reduce or revoke against each entitlement. An entitlement with no recorded decision counts as incomplete, not as confirmed.
Separation-of-duties conflict is tested against a fixed matrix of five incompatible role pairs agreed with the client. A conflict mitigated only by manual convention is reported as a conflict, because it cannot be evidenced after the fact.
Exclusions. Account existence and MFA state are reported monthly in the Account Management report. Tenant-level sharing configuration is reported in the M365 Security report. Physical access to the offices is outside the managed service.
This copy is an anonymised sample prepared for illustration. The client name, system names, role titles, share names and approver identities have been replaced with fictitious or generic values; counts, ratios, dates and findings reflect a representative managed estate. No real client data appears in this document.
BCS Support Center · it-service@brocent.com
Questions clients ask about this report
Every identity's access to every resource at every permission level is presented to a named business approver, who records confirm, reduce or revoke. Brocent never certifies access on the client's behalf — an entitlement with no recorded business decision counts as incomplete, not as confirmed.
Against a fixed matrix of incompatible role pairs agreed with the client — for example creating and approving a payment. A conflict mitigated only by a manual convention is still reported as a conflict, because it cannot be evidenced after the fact.
Quarterly for entitlements and privileged roles is the position most investor due-diligence questionnaires expect, with removal on the day of departure handled by the monthly account process rather than waiting for the review.
See what your own Access & Permission Review report would say
A free IT health check produces a first version of this report against your real estate, at no cost and with no obligation. It takes about a week and needs a few hours of your team's time.