access-audit

Audit access controls across applications, infrastructure, and service accounts.

13|3|Updated Mar 27, 2026
One-click install
npx skills add https://github.com/heaptracetechnology/heaptrace-skills --skill access-audit
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: access-audit
Source: https://github.com/heaptracetechnology/heaptrace-skills/tree/main/compliance/access-audit
Command: npx skills add https://github.com/heaptracetechnology/heaptrace-skills --skill access-audit

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Audits of access controls across applications and infrastructure to ensure least privilege, proper provisioning and deprovisioning, MFA enforcement, break-glass procedures, and audit-ready evidence for compliance programs.

Core Features & Use Cases

  • Map and enforce authorization models (RBAC, ABAC, policy-based) across the stack.
  • Perform end-to-end access audits covering application, infrastructure, and identity lifecycle to identify privilege creep and misconfigurations.
  • Produce evidence aligned to SOC 2 CC6, HIPAA, PCI-DSS, GDPR where applicable, and support auditors during quarterly reviews.
  • Use during onboarding, role changes, offboarding, and when introducing new services or resources to maintain least privilege.

Quick Start

Initiate a comprehensive access audit for your environment by enumerating roles, validating provisioning/deprovisioning, and verifying MFA and break-glass procedures.

Frequently Asked Questions about access-audit

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit access controls for SOC 2 compliance across my infrastructure?

Auditing access controls for SOC 2 compliance involves mapping authorization models like RBAC across your stack, validating provisioning and deprovisioning, and verifying MFA enforcement to produce audit-ready evidence aligned with SOC 2 CC6 controls.

What is the best way to identify privilege creep during user offboarding?

To identify privilege creep during user offboarding, perform an end-to-end access audit covering applications, infrastructure, and service accounts to detect misconfigurations, enforce least privilege, and validate proper deprovisioning of role changes.

Can I enforce least privilege and MFA across service accounts and applications?

You can enforce least privilege and MFA across service accounts and applications by applying RBAC and ABAC authorization models, validating service account ownership, and verifying MFA enforcement during comprehensive access audits.

How do I map RBAC and ABAC authorization models for a compliance audit?

To map RBAC and ABAC authorization models for a compliance audit, enumerate roles across applications and infrastructure, validate policy-based access controls, and align findings with HIPAA, PCI-DSS, and SOC 2 requirements to support auditors.

Does this access audit process cover break-glass procedures and service account ownership?

The access audit process covers break-glass procedures and service account ownership by validating their configuration and mapping them to least privilege policies, producing auditable evidence for compliance programs like HIPAA and PCI-DSS.