Skip to content

Monthly Access Review

Frequency: 1st of each month | SLA: Complete within 5 business days

Each monthly GitHub Issue is auto-populated with access findings from access_review.py, which pulls the live workforce roster from Google Workspace (the authoritative directory), maps each user’s orgUnit to expected system access via role-access-map.yaml, and cross-references against collected evidence. Reviewers validate pre-computed findings rather than pulling data manually.

Each review is tracked as a GitHub Issue using the Monthly Access Review template. For the deeper quarterly review (service accounts, API keys, access levels), see the Access Review Procedure.


StepAction
1. Review findingsOpen the auto-populated GitHub Issue. Evidence has already been cross-referenced against the live Google Workspace roster. Review each flagged account.
2. Validate findingsConfirm flagged accounts are truly unauthorized or departed — not a role mapping issue. Update role-access-map.yaml if the org structure changed, or proceed to remediation.
3. RemediateRevoke unauthorized/departed access using the Remediation Locations table below. Document all actions taken in the GitHub Issue.
4. VerifyRun doppler run -p m7-security -c prd -- python3 automation/scripts/runner.py --mode verify and confirm no new access violations appear.
5. Close issueClosed issue is the audit evidence for the monthly review.

Evidence artifacts land in evidence/logs/<system>/YYYY/MM/ — user lists, role assignments, and API key inventories for each system.

SystemWhere to Revoke/Modify Access
Google Workspaceadmin.google.com > Directory > Users
GitHubgithub.com/orgs/Meridian7-io/people
Slackmeridian7.slack.com > Admin > Manage members
1Password1password.com > Admin console > People
GCP IAMconsole.cloud.google.com > IAM > IAM (meridian7-navi project)
GCP Cloud Monitoringconsole.cloud.google.com > IAM > filter Monitoring roles
Supabasesupabase.com > Org settings > Members
Dopplerdoppler.com > Workplace > People
Cloudflaredash.cloudflare.com > Account > Members
CrowdStrikefalcon.crowdstrike.com > Support > User Management
Backblazesecure.backblaze.com > App Keys


Meridian Seven — Confidential