This is a ready-to-use register. Replace every <<FILL: ...>> placeholder with your own specifics and route completed copies through your normal review and retention process. A worked filled specimen follows the template. Verify each cited regulation against the current source before you rely on it.
Purpose
You cannot control what you have not inventoried. This register lists every account, human or service, that can connect directly to a GxP production database (as opposed to through the application), so that the database-tier bypass risk described in database-layer data integrity can be actively managed rather than assumed away.
Field definitions
| Field | Format | Required | Completed by |
|---|---|---|---|
| Account ID / username | Text, the actual login name | Yes | IT security |
| Account type | Named individual / Application service account / Vendor support / Reporting-integration | Yes | IT security |
| Named individual (if applicable) | Full name | Conditional | IT security |
| Database(s) accessible | List | Yes | IT security |
| Privilege level | Read-only / Read-write (application-mediated only) / DBA (full privileged) | Yes | IT security |
| Business justification | Free text, why this access is needed | Yes | System owner |
| Provisioned date | Date | Yes | IT security |
| Last access review date | Date | Yes | IT security / QA |
| Re-justification status | Justified / Revoked / Pending review | Yes | System owner |
Instructions
- List every account that can open a direct connection to a GxP production database, regardless of how rarely it is used. An account that exists but is never used is still an inventory item and still a risk until formally revoked.
- Application service accounts are listed but flagged as such; they should show read-write access used only by the application, never by a human interactively.
- Reporting or integration accounts should be read-only wherever technically possible; a write-capable reporting account is a finding waiting to happen and should be re-justified or reduced to read-only.
- Re-justify every entry at
<<FILL: frequency, e.g. quarterly>>. An entry that cannot be re-justified is revoked, not carried forward. - Cross-check this register against the DBA segregation reconciliation in
<<FILL: SOP-ID for DBA governance>>and the periodic access review in<<FILL: SOP-ID for access review>>.
Retention
Retain this register, and each superseded version, for <<FILL: retention period>>, consistent with the retention period for the GxP records the underlying databases hold.
Filled sample rows
| Account ID | Account type | Named individual | Database(s) | Privilege level | Justification | Provisioned | Last review | Status |
|---|---|---|---|---|---|---|---|---|
| slindqvist | Named individual | S. Lindqvist | DB-LIMS-01, DB-MES-01 | DBA (full privileged) | Production DBA, LIMS and MES support | 2024-03-01 | 2026-06-30 | Justified |
| jokafor | Named individual | J. Okafor | DB-LIMS-01, DB-MES-01 | DBA (full privileged) | Production DBA, LIMS and MES support | 2023-11-15 | 2026-06-30 | Justified |
| svc_lims_app | Application service account | N/A | DB-LIMS-01 | Read-write (application-mediated only) | LIMS application connection pool; no interactive human use | 2022-06-01 | 2026-06-30 | Justified |
| rpt_qms_readonly | Reporting-integration | N/A | DB-QMS-01 | Read-only | Monthly quality metrics report extraction | 2025-01-10 | 2026-06-30 | Justified |
| tgarcia (former developer) | Named individual | T. Garcia | DB-LIMS-01 | DBA (full privileged) | Original go-live support, project ended 2025-09 | 2024-01-05 | 2026-06-30 | Revoked, access removed 2025-09-30, confirmed absent this cycle |
The last row is the entry an inspector wants to see: an access grant that outlived its business need was found, revoked, and its continued absence re-confirmed at the next cycle, rather than quietly carried forward on an old spreadsheet.
Common inspection findings this register prevents
- “We don’t have a list of who can get into the database directly” as a live answer during an inspection.
- A developer or vendor support account that went live for a project and was never revoked.
- A reporting account with unnecessary write access, never questioned because no one reviews it.
- An account inventory that exists but was last updated years ago and does not reflect current staffing.
How to adapt this register
- Add or remove columns to match your access-management tooling’s actual fields.
- Set the re-justification frequency based on the criticality of the databases in scope.
- Point the cross-references to your real DBA governance and access review procedures.