Delivery kit

Access register — [CLIENT] / [PROJECT]

Last changed 2026-08-18 · all documents · security & deployment

Everything I can get into that belongs to the client, and everything of mine that holds their data. One row per credential or grant. A row is only closed when access is revoked and I have confirmed I am locked out.

Reviewed at: kickoff · delivery · handover. Any row still open at handover blocks the project being called finished.

Last reviewed: [DATE] by [NAME]

Access I hold

#SystemWhat it coversTypeScope / permissionGranted byGrantedRevokedLocked-out verified
1e.g. SharePoint/Ops/Exports onlyApp registrationFiles.SelectedOperations.Selected, read[name]YYYY-MM-DD
2e.g. Drive folder/Ops/Exports onlyService accountShared to SA, viewer[name]YYYY-MM-DD
3e.g. Azure subrg-dashboardsUser accountContributor on one RG[name]YYYY-MM-DD
4e.g. Git repoproject repoPersonal accountWrite[name]YYYY-MM-DD

Getting the grain right matters here. Sites.Selected scopes to a site collection, not to a folder — if the row says one folder, the permission you want is Files.SelectedOperations.Selected, granted on that file or folder. Writing Sites.Selected next to a folder path in this register would record access narrower than what was actually granted, which is the specific failure this document exists to prevent.

5

Type: app registration · user account · API key · service account · shared folder · VPN · SSH key · physical

Access others hold to my side

Anyone I have given access to something of mine that touches this project — subcontractor, client staff on my repo, a support account.

#Person / accountWhat they can reachWhyGrantedRevoked
1

Secrets in play

Names only. Never values.

#Secret nameWhere it livesUsed byLast rotatedRotated at handover
1Key Vault: [name]YYYY-MM-DD

Review log

DateTriggerRows changedNotes
kickoff / delivery / handover / person left / scope change