Monitoring is what keeps an access model honest after the project team leaves. We collect the signals that
describe whether access is behaving, compare them against thresholds agreed with you, and route anything unusual
to a named owner with a response window. Reporting then turns those signals into a monthly picture your
leadership can act on.
We are explicit about what we do not claim: no access model eliminates risk, and we do not offer assurances we
cannot evidence. What we offer is a system that notices, records and explains.
FIG 5 · The estate is watched the way a sector is watched — continuously and with context.
The signals we watch
REF ACC-MON-1020GROUPS FiveOWNERS Named
Authentication. Failed sign-in patterns, locked accounts, sign-ins from unusual locations, and
repeated challenges that suggest a device out of policy.
Access changes. Entitlement changes outside normal hours, privilege grants without a matching
request, and counts of standing access versus just-in-time reach.
Sessions. Privileged session volume, approval latency, sessions on sensitive systems, and any session
that ran beyond its approved window.
Configuration drift. Rules changed since the last review, zoning boundaries altered without a change
record, and policy versions that no longer match the published document.
Service health. Availability of brokering points, gateway capacity, and time to detect and respond
to a degraded path.
The monthly report
REF ACC-MON-1040SECTIONS SevenAUDIENCE Owner and auditor
Each month we publish a report with the same structure, so trends are visible rather than buried. It opens with
a one-page summary for leadership: what changed, what we noticed, what we recommend. Then come the sections
covering access volume and shape, privileged reach and approvals, session review outcomes, exceptions and their
ageing, drift and change control, incidents and responses, and a forward look at the next month’s risks.
Numbers come with context. A rise in failed sign-ins may be a misconfigured device fleet rather than an attack,
and we say which. Reports are written for people who have to make decisions in the next thirty days.
Review routines
REF ACC-MON-1060MEETINGS Monthly + quarterlyESCALATION Defined
Monitoring feeds two recurring conversations. The monthly operations review walks the report with the team that
runs the estate and agrees the actions. The quarterly governance review looks at policy, exceptions and the
design itself, asking whether the model still matches how the organization works.
Deliverables · monitoring configuration, threshold register with owners, escalation paths,
monthly report and the quarterly governance pack. Emergency response support is available on higher retainer
tiers.
We also watch the monitoring itself. A threshold that never fires may be well-tuned or may be misconfigured, and
a report that looks identical every month may mean stability or may mean nobody is reading it. Periodically we
review the signals against real events to confirm the system would have noticed, and we retire rules that have
stopped carrying information.
Reports are also written to be read quickly. Each opens with a summary that fits on one screen, so a busy owner
can grasp the month in a minute and decide whether to read on. Detail is there when it is wanted, never as a
barrier to the headline.