Cybersecurity & Digital Protection · Governance

Account & Access Review

A written picture of who can reach what, across the systems your business runs on

Buy now

$299USD one-off

One payment. Work starts once we have confirmed your requirements.

The four questions this page answers

  1. 1

    What you buy

    A one-off remote review that lists every business system, every account on it and what each account is able to do. Nothing is changed; you receive the register and a set of recommended actions.

  2. 2

    What you get

    5 deliverables, listed in full below

    • A written access register covering every system in scope
    • A flagged list of dormant, shared, over-privileged and leaver accounts
    • A ranked action list, each item naming the system and the change to make
    + 2 more
  3. 3

    How it is delivered

    Remote Setup

    Carried out remotely by our team. Nothing is posted and no one visits.

    REMOTE SERVICE

  4. 4

    How long it takes

    5–7 business days from receipt of visibility on the systems in scope

    Measured from the point everything under “what we need from you” is with us, not from the moment you pay.

A permissions matrix showing who can do what, and who has two-factor enabled — illustrative concept, not a screenshot of a client system
A permissions matrix showing who can do what, and who has two-factor enabled. Illustrative interface concept — not a screenshot of a client deployment.

What is this, in plain English?

A one-off remote review that lists every business system, every account on it and what each account is able to do. Nothing is changed; you receive the register and a set of recommended actions.

Most small businesses cannot answer "who still has access to our systems" without guessing. This produces the answer in writing: a register per system, the logins that look dormant, shared or over-privileged, and the ones belonging to people who left. It is deliberately read-only. Access Control Setup is the product that acts on what this finds.

The problem it solves

A member of staff left eight months ago and nobody is certain whether their logins were ever switched off, or what they could still reach if they were not.

If that does not describe you, this is probably the wrong product. Tell us and we will point you at a better fit rather than sell you the nearest one.

What you get

The concrete things that exist at the end and that you own.

5 deliverables

  • A written access register covering every system in scope
  • A flagged list of dormant, shared, over-privileged and leaver accounts
  • A ranked action list, each item naming the system and the change to make
  • A record of any system we could not see into, and what was needed to see it
  • A handover call to talk through the findings

What's included

The work covered by the figure in the buy box, at no extra cost.

  • Up to fifteen systems reviewed
  • Account-level register with roles and last sign-in where available
  • Cross-check against your staff and contractor list
  • Identification of shared and generic logins
  • Ranked recommended actions
  • Handover call over video

Not seeing something you expected? Check what you are not buying before you order.

What does it do?

Everything listed here is delivered as part of this product. Nothing on this list is aspirational.

  • An access register covering up to fifteen systems, including cloud tools and shared drives
  • Every account listed with its role, its owner and its last sign-in where the system reports one
  • Dormant, shared and generic logins identified and separated out
  • Accounts belonging to leavers and former contractors flagged against your staff list
  • Administrator counts compared with what each role plausibly needs
  • Recommended actions ranked by risk, written so whoever holds the accounts can carry them out

How it works

The delivery sequence from order to handover.

  1. 1

    List the systems

    We build the list with you, including the tools that were signed up for once and forgotten, which are usually the interesting ones.

  2. 2

    Collect the accounts

    Using the visibility you grant, we export or record every account on each system and what it can do.

  3. 3

    Cross-check against people

    Accounts are matched against your current staff and contractor list, and the ones that match nobody are flagged.

  4. 4

    Rank and recommend

    Findings are ordered by risk, with a specific action written against each one.

  5. 5

    Hand over

    You receive the register and the action list on a call, so the reasoning is clear before anyone starts revoking access.

Delivery & fulfilment

Stream Edge Solutions ships nothing. Every package on this site is carried out and handed over remotely — this is exactly what happens after you order.

REMOTE SERVICEHow this is delivered
  1. 1We confirm requirementsWe read what you sent with the order, come back in writing with anything missing, and agree the scope before any chargeable work starts.
  2. 2We build and configure remotelySetup, configuration and testing are done by our team over a remote connection — on your systems or on ours, whichever the package specifies.
  3. 3We hand it overYou receive the working setup, the credentials, the documentation and a walkthrough. Everything built for you is yours at handover.

Carried out remotely by our team. Nothing is posted and no one visits. Typical turnaround: 5–7 business days from receipt of visibility on the systems in scope.

Delivery method
Remote Setup
Expected delivery time
5–7 business days from receipt of visibility on the systems in scope
Measured from the point everything under “what we need from you” is with us — not from the moment you pay.

Full detail of how work is handed over, what happens if requirements are outstanding and how order records are kept is in the Delivery & Fulfilment Policy.

What we need from you

Nothing starts until these are in place, and the turnaround above is measured from that point — not from the moment you pay.

  • A list of the systems the business uses, including the ones only one person touches
  • Read or administrator visibility on each system in scope
  • A current staff and contractor list to check accounts against
  • A named contact who can answer questions about who is who

Who this is for

  • Businesses that have had staff or contractors leave without a formal handover
  • Companies where everybody appears to be an administrator of everything
  • Owners preparing for a client security questionnaire
  • Organisations that have grown past the point of remembering who was given what

Business needs this addresses: Improve operations, Improve IT infrastructure

What's not included

Just as plainly as the list above: the things this package is not.

  • Making any change at all; this engagement is read-only by design, and revoking access is Access Control Setup
  • Systems you are unable to give us visibility of, which are recorded as unknown rather than guessed at
  • Recovering access to accounts nobody in the business can get into
  • Employment, HR or legal advice about a former staff member
  • Certification or compliance sign-off, which we are not able to issue

Anything outside the scope above is quoted separately, in writing, before it is carried out. Nothing is added to your bill without your agreement.

FAQs

Why not just remove the old accounts while you are in there?

Because revoking access is a business decision with consequences we cannot see from a list. An account that looks dormant may be running a scheduled export that quietly matters. We report, you decide, and Access Control Setup carries out the changes with your sign-off.

What if we cannot get into one of the systems?

Then it appears in the report as a system we could not see, along with what would have been needed. Recording a gap honestly is more useful than a register that looks complete but is not. It is also frequently the most revealing finding in the whole review.

Is this an audit in the formal sense?

No. We are not auditors and this carries no regulatory standing. It is an operational review informed by common access-management practice, and it produces the sort of evidence a formal assessor would ask you for. Anyone assessing you formally must do that work themselves.

How long will the register stay accurate?

Until the next person joins, leaves or signs up for a new tool, which in most businesses is weeks rather than years. Treat it as a starting position and a template rather than a permanent record. The joiner and leaver process in Access Control Setup is what keeps it from drifting again.

Refund & cancellation

What happens if you change your mind, and what happens to money already paid.

Cooling-off before work starts
You have 7 days after ordering to cancel while work has not yet begun. Up to 25% may be retained to cover scoping and scheduling already carried out.
Work already done
Once delivery has started, refunds are assessed against the work completed and the deliverables already handed over — the list under “what you get” above is what that assessment is made against. Approved refunds are processed within 14 days.
If we cannot deliver what is described here
You are refunded. The scope on this page is the scope we are held to, which is exactly why the exclusions above are stated before you buy rather than after.

The full terms, item type by item type, are in the Refund & Cancellation Policy. How the work reaches you is covered by the Delivery & Fulfilment Policy.

Not sure this is the right product?

We would rather point you at the right thing than sell you the nearest one. Ask us before you buy — no obligation.

Related products

Others that solve nearby problems, in case this is not quite the right fit.

Or see all 11 in Cybersecurity & Digital Protection.

Contact us