Quarterly Access Review process diagram
This is a worked example. Wavelength built the diagram below from the description on this page. Nobody drew it by hand.
What was said
IT exports the user access list from each system at the start of the quarter. System owners review the list for their system and flag accounts that should be revoked. If an account should be revoked, the owner opens a ticket in Jira. IT disables the account and saves the evidence to a shared drive. If the account should stay, the owner signs off. Security reviews the completed evidence and signs off the quarter.
The diagram
What is in this flow
- Systems: None.
- People and teams: IT, System Owner, Security.
- Decisions: Revoke Account?.
- Size: 12 steps and 12 connections.
Steps
- IT
- Export User Lists (IT)
- System Owner
- Review Access List (System Owner)
- Revoke Account?
- Open Jira Ticket (System Owner)
- Disable Account (IT)
- Save Evidence to Drive (IT)
- Sign Off (System Owner)
- Security
- Review Evidence (Security)
- Quarter Sign-Off
Mermaid code
Copy this into any Markdown file, GitHub README, or Mermaid Live to render the same flow.
flowchart TD
n1(IT)
n2([Export User Lists])
n3(System Owner)
n4[Review Access List]
n5{Revoke Account?}
n6[Open Jira Ticket]
n7[Disable Account]
n8[Save Evidence to Drive]
n9[Sign Off]
n10(Security)
n11[Review Evidence]
n12([Quarter Sign-Off])
n1 -->|exports| n2
n2 -->|sends lists| n3
n3 -->|reviews| n4
n4 -->|decides| n5
n5 -->|Yes| n6
n5 -->|No| n9
n6 -->|assigns to IT| n7
n7 -->|disables| n8
n8 -->|evidence saved| n10
n9 -->|signs off| n10
n10 -->|reviews| n11
n11 -->|signs off quarter| n12
Map your own process
Describe your version out loud, or paste the transcript of a call. Wavelength draws the flow as you talk, and you can edit it by voice, by prompt, or by hand.
Every new account starts with 7 days of Pro. No card needed.
This example is part of our guide for compliance and audit.