Who can reach what.
WHAT TO LIST
Every system and service you use
FOR EACH, CHECK
Who has an account Whether each person still needs it Whether their level is still appropriate Whether any account is shared
THEN CHECK
Applications and integrations with access API keys and tokens issued Remote access permissions Devices with saved sessions
WHAT TO REMOVE
Anyone who has left Access granted for a task that finished Applications you no longer use Keys nobody can account for
THE UNACCOUNTED KEY
Investigate before removing, then remove.
FOR SHARED LOGINS
Replace with individual accounts where possible.
Where not, change the password and record who holds it.
WHAT TO VERIFY
That removal actually took effect.
WHAT TO RECORD
The review and what changed.
WHAT YOU WILL FIND
More than you expect, every time.