Security & Privacy · THE NO-PANIC PLAN
Review an organization’s account inventory without collecting secrets
This procedure reviews an organization’s account inventory; it is not a password vault or a credential-rotation service. Use the organization’s approved identity, directory, HR and application administration systems to identify accounts and verify authorization. Record only the account metadata needed for ownership and review, and never copy passwords, API keys, recovery codes, session tokens or authentication secrets into the inventory. CIS Controls v8.1 Safeguard 5.1 calls for user, administrator and service accounts to be inventoried and active accounts checked for authorization at least quarterly; it lists person, username, start/stop dates and department as minimum user-account data. Safeguard 5.5 separately calls for service-account owner, review date and purpose. Adapt the schedule to your organization’s policy and risk. Keep names and usernames in access-controlled company systems, not in Nirmion or a public page.
MISSION Help an organization verify that user, administrator and service accounts are authorized, assigned to an owner and reviewed on schedule, without placing passwords, recovery codes, tokens or private account data in a public tool.
Review your organization's approved identity systemTHE REAL-WORLD BIT
What happens outside this browser tab?
Set the inventory boundary and review owner; collect account metadata from approved identity and application systems without recording secrets; reconcile the inventory against current users, access approvals and service owners; resolve unknown, dormant or overprivileged entries through approved IAM change controls; then document the review date, decisions, evidence and next quarterly review in the restricted system of record.
YOUR CHECKLIST, WITH FEWER DRAMATIC SIGHES
One step at a time.
Follow the order below. If a step names a Nirmion tool, its link is right there with it.
- 01
Set the review scope and name accountable owners
Choose the business unit, identity providers, directories, operating systems, databases, cloud services and third-party applications included in this review. Include ordinary user accounts, administrator accounts, service accounts and other organization-managed identities; note systems that are excluded and who owns their separate review. Assign an inventory owner and a reviewer authorized to inspect access records. Use the enterprise asset and software lists to discover systems that create or manage accounts, then ask system owners how they identify active, disabled and last-used accounts. Store the review plan in the approved access-controlled location. Do not send company usernames, employee names, system lists or access data to an external checklist or public AI service.
- 02
Collect account records without copying authentication secrets
Export or query account metadata from each approved identity or application administration console using authorized read-only access where possible. For user and administrator records, capture the minimum needed to confirm authorization and accountability, such as person, username, department, start or end date, system, account type, enabled state and review owner. For service accounts, capture the responsible department or owner, purpose, managing system and review date; identify a service-account owner who can confirm continued need. Never include passwords, password hashes, API keys, recovery codes, private keys, session cookies or MFA seeds. Keep extracts encrypted or inside the organization's controlled workspace, limit access to reviewers, and record the export date and source so the inventory can be checked again.
- 03
Compare the inventory with authorized people and service owners
Compare the account export against the current employee/contractor roster, approved joiner-mover-leaver records, the administrator authorization list and service-account owner confirmations. For each active account, confirm that the identity belongs to a current person or documented service, the account has an approved business purpose and the assigned permissions match the role. Mark exceptions separately: unknown owner, person no longer affiliated, missing approval, duplicate account, stale service account, unexpected administrator privilege or missing review date. Do not assume similar usernames are duplicates or disable an account because it looks old; service and emergency accounts can have special owners and change windows. Route each exception to its accountable manager or system owner and preserve the approval evidence in the restricted source system.
- 04
Resolve exceptions through the approved identity-change process
For each confirmed exception, open the organization's normal access-removal, role-change, ownership or incident workflow and obtain the approval required by policy. Have the authorized system owner disable or adjust access in the source identity system; do not treat an inventory spreadsheet as an access-control mechanism. For leavers or urgent suspected compromise, follow the organization's established revocation and incident response process promptly, preserve logs, and avoid deleting evidence. For dormant accounts, apply the organization's documented inactivity threshold; CIS Safeguard 5.3 recommends deleting or disabling dormant accounts after 45 days where supported, but use the threshold and exception process adopted for your environment. Track the ticket/reference, approver, action owner, due date and final confirmation without recording authentication material.
- 05
Approve the review record and schedule the next check
Ask account owners to attest that their active user, administrator and service accounts remain authorized, and record who reviewed each system and when. Reconcile completed access changes back to a fresh system export so the review records the actual disabled or changed state, not only an approval request. Keep a restricted audit trail of system coverage, missing owners, unauthorized accounts found, corrective tickets, exceptions and unresolved risks. CIS Safeguard 5.1 calls for active-account authorization review at least quarterly, and 5.5 specifies at least quarterly service-account reviews; align the next review date with those controls or stricter internal requirements. Escalate unowned accounts and overdue exceptions to the security or business owner. Close the cycle only when the reviewer signs the record and the next review is scheduled.
THE HELPER CREW
Tools for the fiddly bits.
These are the currently published Nirmion tools matched to this guide. Open a tool page for its accepted inputs and limits.
RECEIPTS, PLEASE
Sources & review notes
Each source is linked to the steps it supports. Open it to check its scope and current guidance.
Source checked 2026-10-06
- CIS Controls v8.1 Assessment Specification - Control 5: Account Management
- CIS Critical Security Control 5 - Account Management
- CIS Controls v8.1 - Account and Credential Management Policy Template
- Nirmion production tool catalog search
- Nirmion production workflow search
- NIST SP 800-53 Rev. 5 ? Security and Privacy Controls for Information Systems and Organizations