Security & Privacy · THE NO-PANIC PLAN
Create a non-secret account and access inventory
For an organization or small-team administrator building a restricted, current list of system accounts and access owners. Track who owns each account, why it exists, its access scope and review status. This inventory is not a password vault: never put passwords, API keys, tokens, authenticator seeds, recovery codes or security answers in it.
MISSION create a non-secret account and access inventory
Start this workflowTHE REAL-WORLD BIT
What happens outside this browser tab?
Define which systems and account types are in scope, collect account metadata from approved sources, reconcile it with owners and authorizations, review keep/change/remove decisions through the approved access process, then protect and maintain the inventory as accounts and staff change.
YOUR CHECKLIST, WITH FEWER DRAMATIC SIGHES
One step at a time.
Follow the order below. If a step names a Nirmion tool, its link is right there with it.
- 01
Set scope, owners and approved storage
Have the system and business owners define which identity provider, cloud services, applications and account types are included, such as individual, privileged, vendor, service, temporary, emergency or shared accounts. Assign an account manager, an approver and a review frequency under organizational policy. Decide a minimal metadata schema and store it only in an approved access-controlled system. Keep actual authenticators in a separately approved password or secrets manager, never in this inventory.
- 02
Collect account metadata from authoritative sources
Use approved identity-provider or application-admin exports and confirm them with system owners. For each account, record a non-secret account label, system/provider, account type, owner, business purpose, status, assigned roles/groups and privilege level, MFA enabled/type status, recovery-method status (not the method secret), source/last-verified date and next review date. Include a reference to the authorized vault entry only if policy allows it. Do not collect passwords, API keys, session tokens, private keys, authenticator seeds, recovery codes or security answers.
- 03
Reconcile each account and its authorized access
Compare the list with the directory or identity provider and owner-approved access records. For every entry, confirm the account exists, has a current owner and business purpose, and its roles/privileges are still authorized. Compare changes with joiner, transfer and termination records; flag unknown owners, duplicate/shared accounts, stale access, temporary/vendor accounts past their approved period and privileged accounts for explicit review. Record only a non-secret evidence reference or ticket number. Do not sign in as another person or disable an account during inventory collection.
- 04
Review keep, change or remove decisions
Send each scoped account to its designated owner and approver for a recorded keep, reduce, transfer or remove decision. The published Access Review Checklist can organize that review using non-secret account metadata. Route unclear ownership, admin privileges and exceptions to the system/security owner. Make changes only through the provider approved admin process; before removing an account or recovery method, verify an authorized replacement and required emergency access. Follow policy to change shared/group authenticators when membership changes, but never store the new secret in this inventory.
- 05
Protect the inventory and keep it current
Record the reviewer, decision date, non-secret evidence reference and next review trigger. Restrict access to the inventory, use approved encrypted storage and sharing, and remove temporary exports when policy permits. Reconcile it after account creation, privilege changes, vendor changes and staff transfers or exits. Review exceptions until closed, and periodically check that the inventory itself contains no password, key, token, recovery code, seed or secret-bearing screenshot.
THE HELPER CREW
Tools for the fiddly bits.
These are the currently published Nirmion tools matched to this guide. Open a tool page for its accepted inputs and limits.
RECEIPTS, PLEASE
Sources & review notes
Each source is linked to the steps it supports. Open it to check its scope and current guidance.
Source checked 2026-10-04