Six months after go-live nobody can answer two questions: which accounts hold administrative rights on the appliance, and who or what owns each service identity. Which deliverable, had it existed, would have turned that audit into a fifteen-minute diff?
Select an answer to reveal the explanation.
Short Explanation
The audit felt like archaeology because the as-built identity register - every account, its role, its owner - was never written down while the build was still fresh. With that register, today's question becomes a fifteen-minute diff instead of a month of interviews. Boring paperwork, done while you remember, is the cheapest security tool you'll ever buy.
Full Explanation
The missing deliverable is the unglamorous one that beats anything clever: an as-built identity register written during the build - every account on the appliance, its role, and the person or application that owns it - and maintained as part of configuration work, so state stays true because the last person to touch an account was also the last person to edit the register. Six months later, 'who is admin and who owns what' becomes a diff between the register, the live account list and the directory groups, with every delta surfacing as a reviewable exception instead of an excavation through interviews and memory. A weekly successful-login report measures use, not entitlement: it shows who walked through the door and says nothing about the unused account that still holds admin rights - exactly the finding that matters most in an access review. A change-ticket archive records intent at request time, not present state: it drifts the moment anything happens off-process or in an emergency, and reconstructing today's truth from historical tickets is a project, not a query. A go-live directory export ages the same way the register prevents - point-in-time, no owner mapping, quietly falsified by every change since. Exam caveat: the register's value is the maintenance habit, not the document format; assign ownership of it at handover. Operational check: request the current register and reconcile it against the live account and role list on the appliance; every delta is a finding.