ERP and finance systems
Finance systems where a leaver's access and a shared login matter to the auditor of the financial statements. The checker reads the system column to group the accounts; the findings come from the other columns, the same way for every system.
What the export usually carries
An ERP or finance system export usually carries the user, roles or responsibilities, status, valid-from and valid-to dates and last login. Role names are how privileged access shows, so the member-of or roles column matters most here; shared and generic users are common for batch jobs.
What the checker most often raises here
- 1. A leaver's own account is still enabled: The staff list is pasted, the account belongs to one person (a person or an administrator account, or a contractor whose own code is in the staff list), the staff list says that person left on or before the as-at date, and the account does not read as disabled. With no enabled column it is worded as a question.
- 9. Shared or generic login used by people: The account type is a shared or generic login, from the type column or assumed from the name.
- 5. Privileged, and orphaned or dormant: The account is privileged (its privileged column reads yes, its member-of column names an administrative group, or it is an administrator, break-glass or built-in administrator account) and it carries finding 1, 2, 3 or 4.
- 10. Not reviewed within the interval: The list has a last reviewed column, and this account's cell is blank or older than the interval you set (default 12 months) before the as-at date. With PCI DSS ticked, user accounts also fire at more than 6 months (7.2.4); with CIS Controls ticked, every account at more than 12 months (6.8). Exactly the interval never fires. Without the column, the finding does not fire and every line says the column is missing.
Account types found here
- Built-in or vendor default accounta system account
- Break-glass or emergency accounta user account
- AI agent credentiala system account
- Automation or bot (scheduled jobs, RPA)a system account
- Service accounta system account
- API key or access keya system account
- OAuth client or app registrationa system account
- Device or workload identitya system account
- Mailbox or resource accounta user account
- Test accounta user account
- Shared or generic logina user account
- Administrator or privileged person accounta user account
- Contractor or guesta user account
- Person (employee)a user account
The system names in your export are matched to these classes by the browser dictionary; product names are never shown on these pages. A system the dictionary does not place reads as other, and every finding still works.