Workbook

Supplier Access Review Workbook

Review SaaS integrations, MSP accounts, and vendor access with evidence requests, a worked decision, and a reusable approval record.

Supplier Access Review Workbook visual for DefendArm Security guidance
Preview before download

Inventory the access, not just vendors

Start with suppliers that can administer systems, export sensitive data, change identity settings, or interrupt an important service.

Sample decisions
  • Does the supplier still need each permission, including tokens and delegated grants?
  • Can a narrower role perform the agreed support task?
  • How will the owner verify revocation without disrupting required work?
Common mistakes
  • Reviewing named users while ignoring service principals and API tokens.
  • Keeping access because a contract is still active without checking the task.
  • Assuming disabling a user also revokes every integration credential.
What is inside

Supplier Access Review Workbook

Review SaaS integrations, MSP accounts, and vendor access with evidence requests, a worked decision, and a reusable approval record. Includes a fillable PDF with worked examples and decision records.

Fillable PDF. Reviewed 2026-09-21. Includes practical guidance and reusable review records.

  • Inventory the access, not just vendors: Start with suppliers that can administer systems, export sensitive data, change identity settings, or interrupt an important service.
  • Worked review / Support integration: Fictional example: a support supplier has tenant-wide read/write access, but its current job is to read ticket metadata.
  • Supplier access decision record: Repeat this sheet for each privileged account, integration, or access group. Keep secrets out of the completed workbook.

References

Examples are fictional. Adapt these materials to your environment; completing a worksheet is not a certification.

Questions teams ask

Practical questions before you decide.

Who should use the Supplier Access Review Workbook?

This resource is built for IT owners, procurement, security teams, and service owners who need a clear way to turn security guidance into owners, evidence, and next actions.

What should a team prepare before using it?

Prepare current system owners, relevant policies, available logs or configuration evidence, and any known exceptions that affect the control area.

When should this turn into a deeper review?

Bring in the relevant specialist when the work exposes missing evidence, unclear authority, or controls your team cannot validate. Keep the unresolved issue, owner, and next decision recorded.