Scope: for temporary permissions in one outsourced lane, were rights removed or renewed by expiry? Define system, permission types, window, time zone, and population. Include inactive accounts and exceptions.
Methodology: join requests, permission exports, expiry dates, renewals, and removal logs by stable identifier. Classify removed on time, approved renewal, active after expiry, unverifiable, or out of scope. Verify a subset and preserve extraction times.
CISA, NIST, and GAO support access ownership, least privilege, and evidence quality. They prescribe no universal expiry, certify no system, and demonstrate no provider effectiveness.
Inference limits and limitations: incomplete logs, shared accounts, clocks, emergency access, synchronization, and undocumented approval cause misclassification. A point-in-time audit proves neither continuous compliance nor absence of misuse.