Evidence area
Cyber Essentials user access review
A user access review proves that the right people have the right access — and that leavers, ex-contractors and unused admin accounts have been removed.
Why user access reviews get missed
Joiner / mover / leaver processes are often ad-hoc, and admin accounts accumulate over time. Without a documented review, your assessor has to take your word for it.
Examples of access review evidence
- List of all admin / privileged accounts with owner
- Joiners, movers and leavers process document
- Most recent access review meeting notes
- Evidence that a leaver's accounts were disabled within an agreed timeframe
- Screenshot of group memberships in Microsoft 365 or Google Workspace
- Review of shared / service accounts
How Evaud helps
Recurring review tasks
Schedule quarterly or biannual access review tasks so they actually happen.
Linked to admin accounts
Track admins as part of your asset register and link review evidence directly.
Comments and history
Every change is recorded with who, when and why.
Frequently asked questions
Start building your Cyber Essentials evidence today.
Free to try. No credit card required.