Operating ProcedureExecution layer

Permission and Guest Access Review (QA)

A checklist with 7 steps: Enumerate every external guest seat across active client workspaces.

By InnovaAI ResearchPublished

What are the steps?

checklist

Permission and Guest Access Review (QA)

  1. 01

    Enumerate every external guest seat across active client workspaces

    Pull the guest list from each platform's admin console and reconcile it against the current statement of work. Seats that outlived a finished engagement are the most common source of unintended access.

  2. 02

    Classify each guest by the minimum data they actually need

    Split guests into three tiers: view-only status viewers, comment-and-approve reviewers, and contributors who can create or edit tasks. Most client-side stakeholders only need the first tier.

  3. 03

    Downgrade any guest whose role exceeds their tier

    A client marketing coordinator with full edit rights on a retainer workspace can rename stages, close tasks, and distort delivery reporting. Reset to the tier you assigned, then document the change.

  4. 04

    Confirm client-side approval before removing or restricting a named guest

    Send a short list of proposed changes to the client's primary contact and get written sign-off. Silent revocations create friction at the next status call.

  5. 05

    Check that shared views and dashboards do not leak internal fields

    Client-facing dashboards frequently inherit columns for internal cost rates, margin, or team utilization. Verify each shared view hides those fields before the client opens it.

  6. 06

    Set a recurring 30-day review tied to contract renewal dates

    Access drift accumulates between renewals. Anchor the review to the renewal calendar so the audit happens before the next scope conversation, not after a client asks why a former contractor still has a login.

  7. 07

    Log the review outcome in the client record with a named owner

    Record who reviewed, what changed, and the date. When a client asks for an access history during procurement or a security questionnaire, this log is the answer.