Audit type

Access and permission audit

1–2 weeks From RM 6,800 Role map, excess-access findings, and a leavers checklist

Colleagues in a meeting room discussing a document on screen

Permission models are often set on go-live day and then quietly stretched. A contractor keeps a login. A manager asks for ‘view all’ during a quarter-end scramble and never gives it back. Someone exports the whole contact list to Excel because a report was slow.

We read the roles against the work. We look for shared credentials, dormant admin seats, and the ability to export or mass-edit without a second pair of eyes. The findings are written for an operations lead and an IT owner, not as a scare document.

Malaysian organisations handling customer data also have Personal Data Protection Act duties. We note where access patterns would be hard to explain if a record were questioned. We are not your legal counsel; we are the people who can show what the application currently allows.

What is in the engagement

  • Role and profile review against the jobs people actually do
  • Leaver and shared-login sampling
  • Export, delete, and admin-privilege notes
  • A practical checklist for the next person who leaves the company

Fees are informational. We confirm the figure after the scoping call, against the size of the organisation and the state of the file. Payment is by invoice; there is no online checkout.

Request this audit

All audit types · How the method runs