Independent and not affiliated with the FDA, MHRA, ISPE, PDA, or any agency. Get the appgoutham@madhadi.com
madhadi.comData Integrity & GxP Quality
Browse all topics → Articles Templates & Procedures Learning paths GlossaryScenariosToolsRegulatory ReferencesLearning PathsTopics About Start here
Log Plug-and-play starting point CSV / CSA

Register: Privileged Database Access Account Inventory

A plug-and-play register of every account that can connect directly to a GxP production database, the first control in closing the database-tier bypass gap: account type, privilege level, business justification, and periodic re-justification, with a filled specimen.

Document type: Log

Read and copy the template below into your own quality system. It is a generic starting point for your own internal use, provided as is, with no warranty; see the Terms and License. Adopting it does not by itself create compliance.

This is a ready-to-use register. Replace every <<FILL: ...>> placeholder with your own specifics and route completed copies through your normal review and retention process. A worked filled specimen follows the template. Verify each cited regulation against the current source before you rely on it.

Purpose

You cannot control what you have not inventoried. This register lists every account, human or service, that can connect directly to a GxP production database (as opposed to through the application), so that the database-tier bypass risk described in database-layer data integrity can be actively managed rather than assumed away.

Field definitions

FieldFormatRequiredCompleted by
Account ID / usernameText, the actual login nameYesIT security
Account typeNamed individual / Application service account / Vendor support / Reporting-integrationYesIT security
Named individual (if applicable)Full nameConditionalIT security
Database(s) accessibleListYesIT security
Privilege levelRead-only / Read-write (application-mediated only) / DBA (full privileged)YesIT security
Business justificationFree text, why this access is neededYesSystem owner
Provisioned dateDateYesIT security
Last access review dateDateYesIT security / QA
Re-justification statusJustified / Revoked / Pending reviewYesSystem owner

Instructions

  1. List every account that can open a direct connection to a GxP production database, regardless of how rarely it is used. An account that exists but is never used is still an inventory item and still a risk until formally revoked.
  2. Application service accounts are listed but flagged as such; they should show read-write access used only by the application, never by a human interactively.
  3. Reporting or integration accounts should be read-only wherever technically possible; a write-capable reporting account is a finding waiting to happen and should be re-justified or reduced to read-only.
  4. Re-justify every entry at <<FILL: frequency, e.g. quarterly>>. An entry that cannot be re-justified is revoked, not carried forward.
  5. Cross-check this register against the DBA segregation reconciliation in <<FILL: SOP-ID for DBA governance>> and the periodic access review in <<FILL: SOP-ID for access review>>.

Retention

Retain this register, and each superseded version, for <<FILL: retention period>>, consistent with the retention period for the GxP records the underlying databases hold.

Filled sample rows

Account IDAccount typeNamed individualDatabase(s)Privilege levelJustificationProvisionedLast reviewStatus
slindqvistNamed individualS. LindqvistDB-LIMS-01, DB-MES-01DBA (full privileged)Production DBA, LIMS and MES support2024-03-012026-06-30Justified
jokaforNamed individualJ. OkaforDB-LIMS-01, DB-MES-01DBA (full privileged)Production DBA, LIMS and MES support2023-11-152026-06-30Justified
svc_lims_appApplication service accountN/ADB-LIMS-01Read-write (application-mediated only)LIMS application connection pool; no interactive human use2022-06-012026-06-30Justified
rpt_qms_readonlyReporting-integrationN/ADB-QMS-01Read-onlyMonthly quality metrics report extraction2025-01-102026-06-30Justified
tgarcia (former developer)Named individualT. GarciaDB-LIMS-01DBA (full privileged)Original go-live support, project ended 2025-092024-01-052026-06-30Revoked, access removed 2025-09-30, confirmed absent this cycle

The last row is the entry an inspector wants to see: an access grant that outlived its business need was found, revoked, and its continued absence re-confirmed at the next cycle, rather than quietly carried forward on an old spreadsheet.

Common inspection findings this register prevents

  • “We don’t have a list of who can get into the database directly” as a live answer during an inspection.
  • A developer or vendor support account that went live for a project and was never revoked.
  • A reporting account with unnecessary write access, never questioned because no one reviews it.
  • An account inventory that exists but was last updated years ago and does not reflect current staffing.

How to adapt this register

  1. Add or remove columns to match your access-management tooling’s actual fields.
  2. Set the re-justification frequency based on the criticality of the databases in scope.
  3. Point the cross-references to your real DBA governance and access review procedures.
Use madhadi.com as an app Full screen, works offline, one tap from your home screen.