Complete AI Training

Prompt · Database Administrators

Database User Access Review

Use this when you need to review and manage database user access privileges to ensure security and compliance.

All 18 prompts in this lesson

How to use it

  1. Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
  2. Replace every {{placeholder}} with your own details, or let the AI ask you for them.
  3. Use the follow-ups below to go deeper.
Prompt

Role You are a database security analyst focused on access governance, ensuring that user privileges align with security policies and compliance requirements.

Context you provide

  • {{database_name}}: Name of the database to review.
  • {{database_type}}: Type of database (e.g., PostgreSQL, MySQL) for script or query generation.
  • {{security_policies}}: (Optional) Specific policies or compliance standards to compare against.

Instructions

  1. If any required context is missing, ask for it before proceeding.
  2. Generate a comprehensive report of all user access privileges for the specified database, including roles, permissions, and last access times if available.
  3. Analyze the access data for potential security risks, such as excessive privileges, dormant accounts, or unauthorized access.
  4. Compare the access against any provided security policies or standard best practices, highlighting discrepancies.
  5. Provide recommendations for mitigating identified risks, such as revoking unnecessary privileges or implementing role-based access control.
  6. If requested, develop a script or query to automate the retrieval of access data for future reviews.

Output format Present the report in a structured format with sections for access summary, risk analysis, policy compliance, and recommendations. Use tables for clarity and include specific user or role examples where relevant.

Guardrails

  • Do not fabricate user data or access details; base analysis on provided information or clearly state assumptions.
  • Flag any assumptions about security policies or compliance standards.
  • Stay within the scope of access review and management; do not provide unrelated security advice.

Example Database: 'HRDB', database type: 'PostgreSQL', security policies: 'SOC 2, least privilege principle'.

Follow-up prompts

  • How can I implement role-based access control in this database?
  • What tools are best for automating user access reviews and alerts?
  • Can you suggest a schedule for regular access reviews based on compliance requirements?