Title: SCL Application Access Control Policy & Procedure
Section: 1.0
Effective Date: September 1, 2021
Revision Date: July 9, 2024
PURPOSE
To provide a policy and procedure to ensure unit-supported system access is updated for staff position changes or terminations.
SCOPE
All Student and Campus Life Applications Access
ROLES & RESPONSIBILITIES
Supervisor
Notify the system administrators to remove access to unit systems through timely responses to TDX tickets to confirm an account needs to remain active or should be deprovisioned.
Submit access requests through the TDX ticketing system for new employees.
System Admin (SSIT or Unit)
Manage access to applications for all users that have joined Cornell, departed, been reassigned, or promoted from unit systems
SSIT
Regularly review and maintain comprehensive list of attributes for all SCL owned and supported applications.
Manage API for Human Resources data feed.
Maintain TDX ticket routing rules, template updates, and messaging content.
SCL Compliance Team
Request user lists from System Administrators.
Manage ticket exceptions.
Toubleshoot overdue pending tickets.
Provide audit report to SCL leadership, upon request.
REVIEW PROCESS
SCL Compliance Team initiates request to System Administrators for updated user list and attestation.
System Administrator uploads user list and submits attestation.
API feed provided by Human Resources integrates with nightly updates.
Employee profiles are flagged when there is a change in employment. This is an ongoing process, with regular data feed updates.
Automated TDX tickets are sent to managers to approve or request removal of user account when an employee profile shows a change of title, supervisor, or employment status.
Managers confirm (approve) continuation of user account or request removal of access by marking the appropriate action on the TDX ticket.
Tickets marked with continuation of user account are automatically closed and moved to archive in TDX.
System Administrator receives removal request for TDX tickets where the manager has indicated that a user account is no longer needed. System Administrator removes access and marks TDX ticket as closed.
Managers may view employee profiles and request access changes at any time.
SCL Compliance Team manages ticket exceptions and facilitates timely resolution of all tickets.
SCL Compliance Team provides audit report to SCL leadership, upon request.
AUDIT CYCLE
Random audits to validate data integrity to SCL compliance team may be conducted.