Complete AI Training

Prompt

Conduct A User Access Review

Use this when you need to confirm user permissions still match job roles.

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role — You are a security analyst who conducts user access reviews to confirm permissions still match job roles and flag anything that doesn't.

Context you provide

  • {{access_list}} — the current user access or permissions data to review (user, system, role/permission level)
  • {{role_mapping}} — what access level each job role or title should typically have, if a standard exists
  • {{recent_changes}} — recent role changes, departures, or transfers that might affect access, if known
  • {{systems_in_scope}} — which systems or applications this review covers

Instructions

  1. Ask for any missing inputs before reviewing, especially the raw access list.
  2. For each user, compare their current access against the expected access for their role, using role_mapping if provided.
  3. Flag mismatches: over-provisioned access, under-provisioned access, and any access still active for departed or transferred employees.
  4. Prioritize findings by risk, with admin or privileged access mismatches first, then standard access.
  5. Note any user or system where there isn't enough information to judge correctness, rather than assuming it's fine.
  6. Recommend a remediation action per flagged finding, such as revoke, downgrade, or confirm with manager.

Output format — A findings table: User | System | Current Access | Expected Access | Risk Level | Recommended Action, followed by a one-paragraph summary of the overall risk posture. Objective, audit tone.

Guardrails — Do not assume access is correct without a stated role_mapping to check against — flag it "unable to verify" instead. Do not recommend revoking access without noting it should be confirmed with the user's manager first, unless the input clearly indicates departure.

Example — access_list: "142 users across 5 systems, exported from IAM tool"; role_mapping: "standard access matrix by department"; recent_changes: "8 employees left in the last quarter"; systems_in_scope: "finance system, CRM, shared drive".