User access review template for Excel
A user access review works per account, not per system: who owns it, when it was last used, when its credential last changed, when it was last reviewed. Download the columns as a CSV and open it in Excel, fill it in from your exports, one line per account, then paste it back and the checker reads it. The export you already pull works too: a column the checker cannot find is reported as not recorded.
Columns the checker reads
header names are matched loosely| Column | What goes in it | Needed |
|---|---|---|
| Account | the login, user principal name, key id or client id; masked codes work | required |
| Type | person, contractor, shared login, service account, API key, OAuth client, AI agent, automation, break glass, built-in, administrator, test, device, mailbox | strongly advised |
| System | directory, cloud platform, database, CI/CD, a SaaS application, and so on | advised |
| Owner | one person, by name or code, or a team | required |
| Accountable person | when the owner is a team, the one person accountable for the account | when a team owns it |
| Enabled | yes or no | strongly advised |
| Last used | a date, "never", or a day count such as 120 days | strongly advised |
| Last changed | the date the password, key or secret was last changed, or "never" | strongly advised |
| Created | a date; read when last used says never | advised |
| Privileged | yes or no, or the administrative role | advised |
| Interactive login | yes or no: can a person sign in to it | for service accounts |
| MFA | yes or no | for user accounts |
| Stored in | vault, code, config file, script, a document, or unknown | for service accounts and keys |
| Last reviewed | the date of the last access review of this account | strongly advised |
| Approval | the ticket or request reference | advised |
| Notes | anything else, as a short label; never a password | optional |
A first line for the periods
regimes: ISO/IEC 27001, SOC 2, PCI DSS | dormant after: 90 days | rotate within: 365 days | review every: 12 months | as at: 2026-09-28
The first line is optional. The ticks on the page do the same; a staff list goes in the second box, or under a line reading --- staff list --- at the end of the same paste.
The four rows in the CSV
invented| Account | Type | Owner | Last changed | Last reviewed |
|---|---|---|---|---|
| E2001 | person | E2001 | 2026-09-20 | none recorded |
| svc-invoice-export | service account | E2002 | 2026-09-27 | vault |
| agent-support-drafts | AI agent | none named | 2026-09-27 | vault |
| frontdesk | shared login | Facilities team | 2026-09-26 | none recorded |
Fill it in, paste it back: each line comes back with its owner and their status, the day counts, the findings and the clauses, and the review sheet export adds blank reviewer, decision, date and ticket columns for the review itself.