ITDR · Access Review & Evidence
This is the report your auditor gets.
A complete, unedited sample of what the self-serve access review produces for a GitHub organization: every finding, the decision made on it, who made it, why — and the objections raised along the way. Run one for your own org in minutes.
Specimen
Everything below is synthetic. The organization, accounts, and timestamps are fictional, generated to show the exact shape and depth of a real report. Counts are point-in-time at snapshot; the tables record only objects that triggered a finding.
47
Members examined
17
Integrations
6
Outside collaborators
21
Findings flagged
9
Marked for revocation
3
Accepted exceptions
03
Privileged members
source · /orgs/{org}/members + memberships| Account | Privilege | Decision | Justification |
|---|---|---|---|
| mona-okafor | Owner | Keep | Security lead; access required. |
| d-rivera | Owner | Flag | Second owner; no activity 41d. Confirm next cycle. |
| ci-bot-admin | Org admin (machine) | Flag | Service account holds org admin. Scope down to repo-admin; track as non-human identity. |
04
Outside collaborators
source · /orgs/{org}/outside_collaborators| Account | Access | Decision | Justification |
|---|---|---|---|
| ext-bferns | 2 private repos | Revoke | ACME audit engagement ended 2026-05-09. Remove access. |
| ext-kpatel | 1 private repo | Keep | Active SOW through Q3 2026. Exception logged. |
05
Installed apps & OAuth grants
source · /installations + audit log| Integration | Permission scope | Decision | Justification |
|---|---|---|---|
| Vercel (app) | contents:rw · deployments | Keep | Approved CI/CD integration. |
| Snyk (app) | contents:r · checks:w | Keep | Security scanning; approved. |
| grafana-oauth | repo (full) | Revoke | Authorized 2025-11 by departed employee; no current owner. |
| screenshot-bot | repo · read:org | Flag | Low usage, broad scope. Confirm owner or revoke next cycle. |
06
Two-factor authentication gaps
source · /orgs/{org}/members?filter=2fa_disabled| Account | State | Decision | Justification |
|---|---|---|---|
| t-nguyen | 2FA disabled | Revoke | Suspend until 2FA enabled; member notified. |
| s-abboud | 2FA disabled | Flag | Enforce within 7 days; re-check next snapshot. |
| legacy-deploy | password auth (machine) | Flag | Migrate to GitHub App token; retire password auth. |
07
Dormant accounts · ≥ 90 days
source · audit log last-activity · threshold 90d| Account | Last activity | Decision | Justification |
|---|---|---|---|
| p-santos | 2026-02-18 · 116d | Revoke | Offboard confirmed by manager. |
| a-cohen | 2026-03-02 · 104d | Revoke | No activity; left team Q1. |
| old-intern-2025 | 2025-12-10 · 186d | Revoke | Internship ended; remove. |
| m-bianchi | 2026-03-05 · 101d | Keep | On parental leave; retain per HR. Exception. |
| vendor-readonly | 2026-02-25 · 109d | Revoke | Vendor engagement closed. |
Run this on your own org today.
Sign in with GitHub, connect an org through our read-only App, and your first review looks exactly like this — with your names on the decisions.
$15/month · 3 scans included · Cancel anytime