‹ IT & Security recipesIT & Security · Agent Blueprint

Access review

Who has access to what, and why. Every grant and exception traced to the request and the approver.

Best forPeriodic access reviews, audits, offboarding sweeps
PrimitivesAccessActorsProvenance

Side by side: token usage, with and without Paperbase

~99k tokens saved · 76% less work for the agent

Without Paperbase

~130k tokens

  1. Export current access from the identity provider.
  2. Compare against the org chart manually.
  3. Search email and Slack for access requests and approvals.
  4. Reconstruct why each grant exists from memory.
  5. Flag nothing, because every grant looks someone else's mistake.

With Paperbase

~31k tokens

  1. Pull current Access across systems.
  2. Pull the approval record behind each grant - request, approver, date.
  3. Ask Paperbase to match grants to current roles and people.
  4. Surface orphaned or over-broad access with their history.

Agent prompt

You are running an access review.

Using Paperbase:

1. Pull current Access across systems, by actor.
2. For each grant, pull the request and approval that produced it.
3. Match access to current roles and employment.
4. Flag orphans, over-broad grants, and long-unreviewed exceptions.

Output:

- The access inventory with provenance per grant.
- Flagged access: orphaned accounts, excessive scope, stale exceptions.
- For each flag: the history, why it may no longer be justified, and a review owner.

Placeholders in {double_braces} are inputs the agent will ask for at runtime. Give the prompt to any agent connected to Paperbase, and the rest grounds in your own memory graph.

Want a deeper recipe for your team?

Send us the prompt, the source systems, and the workflow. We will draft the recipe and sign you into the sandbox to run it.