Practitioner template

User Access Review

Evaluate current user and service-account access against approved GxP roles, responsibilities, least privilege, and segregation of duties.

Author
CSVtoCSA editorial
Published
12 September 2026
Last reviewed
2026-09-12
Version
1.0
Content type
Template
Primary references
Apply the sources and approved procedures relevant to the system
Download Template

Blank template

  1. System and review period
  2. Approved GxP and privileged roles
  3. User or service account
  4. Current job responsibility and owner
  5. Assigned access
  6. Access appropriate
  7. Segregation of duties
  8. Inactive or terminated status
  9. Exception and expiry
  10. Action and completion evidence
  11. Reviewer and approver
  12. Conclusion and next review

Completed fictional example

Fictional teaching example: This is not an executed or approved validation record.

System and review period
Fictional eQMS; annual review
Approved GxP and privileged roles
Investigator, Quality approver, administrator, read only
User or service account
Former Quality reviewer now IT support
Current job responsibility and owner
Application support; IT manager
Assigned access
Quality approver and administrator
Access appropriate
No; approval is not required for support
Segregation of duties
Approval plus administration creates conflict
Inactive or terminated status
Active employee; employment alone does not justify role
Exception and expiry
Temporary support exception expires in five days
Action and completion evidence
Approval removed; ticket-based elevation retained; activity reviewed
Reviewer and approver
Process owner and Quality approval
Conclusion and next review
Appropriate after removal; next scheduled or role-change review