09 May 2026 · 5 min
Reconciling SaaS access logs with written policy
Policy says quarterly access reviews. Logs show orphaned admin seats from a contractor who left in February. Auditors will find both.
09 May 2026 · 5 min
Policy says quarterly access reviews. Logs show orphaned admin seats from a contractor who left in February. Auditors will find both.
Fintech stacks lean on SaaS for CRM, support, data warehouses, and deploy tooling. Each tool has its own export format. Written policy rarely lists them all, which is how “complete coverage” claims unravel.
Start with blast radius, not with the IT asset list. If a role can change payouts, view KYC documents, or push production code, it belongs in the access control story even if the license sits under a marketing budget.
For every claim — joiner provisioning within 24 hours, leaver removal within 48 — store the exact admin path or API call used to evidence it. When the vendor UI changes, update the recipe the same week.
Do not wait for the quarterly ceremony. A short monthly compare of privileged roles versus HR status catches drift early. Document exceptions with ticket IDs; that trail becomes your sample-ready population later.
If one legacy admin console still needs a manual checklist, write it as a compensating control with an owner. Pretending automation is universal is a faster path to findings than admitting a narrow manual step.
The Access & Change Control short course walks through this loop with critique. See the catalog or contact the desk.