Purpose of the Template
Your team regularly provisions service accounts, API keys, and machine credentials. Fast forward six months, and you're faced with hundreds of non-human identities with unexplained access. This template structures quarterly entitlement reviews for service accounts, cloud workload identities, and automated processes. These non-human principals now outnumber your employees.
Use this template when managing access for AI agents, CI/CD pipelines, infrastructure-as-code workflows, or any automated service authenticating to your applications, databases, or cloud resources. It's designed for environments where non-human identities have proliferated beyond what traditional Role-Based Access Control can handle.
Prerequisites
Before starting this review, ensure you have:
Inventory baseline: A list of service accounts, service principals, managed identities, and API credentials across your environment. If you lack this, your first task will be discovery. Expect to find unknown credentials.
Owner attribution: Each service account needs a named owner or responsible team. "Legacy system" or "DevOps" isn't sufficient. You need a person who can confirm whether the access is still required.
Access logs: At a minimum, last authentication timestamp for each credential. Ideally, you have 90 days of access patterns showing what resources each identity actually touches.
Approval authority: Clear decision rights for revoking access. Your template is useless if you can't act on what you find.
The Template
Copy this into a spreadsheet or your governance tool. One row per non-human identity:
SERVICE ACCOUNT ENTITLEMENT REVIEW
Review Period: [Quarter/Year]
Review Owner: [Name]
Completion Deadline: [Date]
COLUMN A: Identity Name/ID
COLUMN B: Identity Type (Service Account | Managed Identity | API Key | Service Principal | Bot/Agent)
COLUMN C: Owning Team/Department
COLUMN D: Named Owner (Individual)
COLUMN E: Business Purpose (What process uses this?)
COLUMN F: Systems/Resources Accessed
COLUMN G: Privilege Level (Read | Write | Admin | Privileged)
COLUMN H: Last Authentication Date
COLUMN I: Creation Date
COLUMN J: Scheduled Rotation Date (if applicable)
COLUMN K: Review Status (Active | Dormant | Unknown)
COLUMN L: Access Justification Required? (Yes/No)
COLUMN M: Owner Confirmation (Confirmed | Revoke | Reduce Scope)
COLUMN N: Action Taken
COLUMN O: Action Date
COLUMN P: Next Review Date
DECISION CRITERIA:
- Dormant = No authentication in past 90 days
- Unknown = Owner cannot explain business purpose
- Revoke = Dormant AND no valid justification provided within 5 business days
- Reduce Scope = Active but privileges exceed demonstrated usage pattern
Add a summary section at the top of your sheet:
REVIEW SUMMARY:
Total Non-Human Identities: [count]
Identities Reviewed: [count]
Dormant (>90 days): [count]
Revoked This Period: [count]
Privileges Reduced: [count]
Identities Requiring Rotation: [count]
Identities with Unknown Owner: [count]
Customizing the Template
Adjust the dormancy threshold: Ninety days works for most environments. If you're running batch processes quarterly, extend it to 120 days. In a high-velocity DevOps shop, consider 60 days.
Add compliance columns: If you're mapping to ISO/IEC 27001 Annex A 9.2.1 or NIST Cybersecurity Framework PR.AC-4, add a column for control mapping. Same if you're tracking Privileged Access Management scope for audit.
Expand privilege classification: The template uses Read/Write/Admin/Privileged. Refine this to match your environment. Cloud teams might need "Contributor/Owner/Reader" mapped to Azure roles. Database teams might need "SELECT/INSERT/DELETE/DBA" granularity.
Layer in risk scoring: Add columns for sensitivity of accessed data (Public/Internal/Confidential/Restricted) and calculate a risk score: Dormant Admin on Restricted data scores higher than Active Read on Public data.
Separate credential rotation tracking: If your service accounts use static credentials, add rotation tracking. Flag any credential older than your rotation policy, typically 90 days for high-privilege, 180 for standard.
Include Just-in-Time Access exceptions: If you've implemented temporary elevation for certain workloads, track the maximum session duration and whether it's being honored.
Validation Steps
Week 1: Discovery and assignment
Export your identity list from Active Directory, Azure AD, AWS IAM, or your cloud provider's identity service. Merge service accounts from application databases, API gateways, and CI/CD tools. You'll find forgotten credentials.
Assign each identity to an owner. Send the template to each team with their rows pre-populated. Give them five business days to confirm or challenge the data.
Week 2: Owner review
Owners fill in Column M (Confirmed/Revoke/Reduce Scope) and Column E (Business Purpose). If they can't explain what a service account does, it's a candidate for revocation. "Probably still needed" isn't confirmation.
Flag any identity with admin or privileged access that hasn't authenticated in 90 days. These require automatic review by your security team, not just the owner.
Week 3: Action and remediation
Revoke dormant accounts with no justification. Don't just disable them, actually remove the credentials. Disabled accounts are technical debt that'll cause issues in the next audit.
For "Reduce Scope" decisions, document the current privilege level and the new target. If a deployment pipeline has Owner rights on a subscription but only deploys to three resource groups, scope it down to Contributor on those groups only.
Rotate any static credentials that exceeded your rotation policy. If you find credentials that predate your current team, rotate them immediately and document the owner gap.
Week 4: Documentation and metrics
Complete the summary section. Calculate your revocation rate (revoked / total reviewed). If it's under 5%, you're probably not being aggressive enough. If it's over 30%, you've got a provisioning problem upstream.
Document any identities where you couldn't determine the owner or purpose. These are your highest risk, they represent access you're managing but don't understand. Escalate them.
Set the next review date. Quarterly is the minimum for environments where AI agents and cloud workloads are proliferating. Monthly isn't unreasonable if you're scaling automation rapidly.
Continuous Validation
Don't wait 90 days to act on new dormancy. Set up alerts for service accounts that go 60 days without authentication. If a deployment pipeline stops running, you want to know before the next quarterly review.
Track your "unknown owner" count over time. It should trend toward zero. If it's growing, your provisioning process is broken, you're creating identities faster than you're documenting them.
Cross-reference your revoked list against incident reports. If you revoked an identity and nothing broke, it was genuinely unused. If something failed, you've discovered undocumented dependencies, fix your documentation, not just the access.
This template won't prevent your team from creating the next orphaned service account. But it'll help you find it before an auditor does.





