Access
Capturing before/after values for privileged access
A ticket that says “granted AP manager role” is not an audit trail. Reviewers need the contents of the role before and after the change — which apps, which company codes, which approval limits — plus who authorized the grant.
Snapshot on the way in
Before assigning or altering a privileged role, export the current assignment and the role definition. Store both with the request ID. After the change, export again. Diff tools help, but a human still confirms that emergency access was removed on schedule.
When the ERP log is thin
Some cloud tenants record that a role changed without listing object-level details. In that case your before/after exports become the primary evidence. Automate them if volume is high; do not rely on memory during busy closes.
SOD overrides
Overrides deserve the same treatment: prior conflict status, new status, compensating control referenced, and expiry. Permanent overrides should appear on a manager dashboard monthly, not only when auditors ask.
Chat is not a log
If emergency access is approved in messaging apps, either route approvals into a system that retains them or accept that your trail is incomplete. Courses can teach documentation habits; they cannot invent storage your organization refuses to fund.
Deepen this topic in the Privileged Access Trail Clinic or module four of the flagship course.