Date Created: May 29, 2025

Last Updated: January 20, 2026

Criticality: Moderate/High

Frequency: Daily


  • SCL Applications Access Controls Project Team: Manage data feed and access to SCL Compliance Database.
  • SCL Compliance Team: Oversee movement of TDX tickets through the workflow and follow up with managers and application administrators to ensure appropriate and timely access requests and closures. Includes managing process of requesting user lists from application administrators, manage TDX ticket flow by manually issuing ticket to the employee’s manager (7 days or less before effective date of the employment status change) and meeting with managers and application admins to resolve questions and tickets that aren’t responded to. Meet with managers and application administrators to educate and manage accountability for responsibilities. Prepare and submit audit report (each semester or upon request) to Student & Campus Life leadership for high-risk applications with user accounts. Audit application profiles to ensure accurate information.
  • SSIT Service Managers: Compile and maintain attribute details for each application owned or managed by Student & Campus Life. Facilitate application ownership discussions and manage data in SCL Compliance Database.
  • Application Administrators: Create user accounts and manage access privileges. Upload user lists to the SCL Compliance Database upon request and as needed for current roster tracking. Assign and deprovision access, when need is warranted and approved by employee’s manager.
  • Managers: Timely responses to confirm when access should be assigned and deprovisioned.
  • Human Resources: Collaborate with Applications Access Controls Team to maintain data feed of employment change data.
  • Student Services Information Technology (SSIT): Triage access request tickets.
  • Employees: Complete data agreement and attest to understanding and adherence with university policies around data stewardship and custodianship, ethical conduct, and retention of university records. Required upon hire for all, subsequent renewal cycle unique to individual applications.


  • SCL Compliance Database
  • TeamDynamix (TDX)
  • Workday
  • Email
  • SCL Owned or Managed Applications


  • Coding of employment change sometimes occurs after the effective date and causes delay in addressing access need.
  • Changes in manager’s employment status may occur midstream the process and the notifications are not dynamic, so the manager contact information does not match the employee’s current supervisor.
  • Data feed and database maintain one manager for each employee. Employment change notifications may route to the manager who is not responsible for authorizing the access needs related to the notification request.
  • Access changes do not occur in real time because the applications and notification processes are independent and require human manipulation that can be prone to error or misjudgments.
  • Communication between compliance with educational training required for access to applications is decentralized.
  • Individuals who hold multiple campus positions may need access to an application to fulfill responsibilities related to their secondary position.


  1. SSIT maintains application profiles, system owners, application administrator’s tables in SCL Compliance Database.
  2. Managers request access for new hires or employees with change in employment by referencing the ‘Request Application Access’ table in SCL Compliance Database.
  3. Application administrators create user accounts and manage access privileges.
  4. Application administrators upload user list upon request (quarterly).
  5. HR data feed connects to SCL Compliance Database and flags records for individuals with a change in employment status.
  6. SCL Compliance Team monitors flagged records and manually initiates ticket when the effective date is within seven days of the review.
  7. Manager receives ticket and confirms whether access should remain or be restricted. Unanswered tickets that extend three weeks beyond the initiation date are moved to application administrator for closure of the user account.
  8. Tickets that are approved for continuing access are closed and archived through automation.
  9. Application Administrators receive tickets requesting access deprovisioning, disable the individual’s access to application(s), update the user list in the SCL Compliance Database, and confirm the closure on the TDX ticket.


Key Risks

Key Controls

Administrative delays and errors in restricting access.

The SCL Compliance Tracking Database tightens notification of changes and improves communication around access needs.

Compiling of user lists is prone to errors and time consuming for application administrators who manage applications that do not allow user account data to be exported.

AAC is increasing awareness and providing education around timeline for requesting updated user lists on quarterly cycle.

No crosscheck for real-time access comparison.

AAC requires user lists to be uploaded on a quarterly basis and encourages more frequent updates in the SCL Compliance database.

Communication between compliance with educational training required for access to applications is decentralized.

AAC project team will soon begin phase three to pivot the SCL Compliance database from an application centric focus to an employee focus that adds the tracking of educational training requirements.

Individuals who hold multiple campus positions may need access to an application to fulfill responsibilities related to their secondary position.

AAC created a response option for ‘I am not the supervisor for the role in question’ that routes to a pending cue managed by SCL Compliance. SCL Compliance checks employment status in Workday, consults with managers and application administrators, determines access needs, and manages the ticket flow.

Administrators may assign users with broader access than what is needed for their responsibilities.

Employees should be given the minimum access privileges to fulfill responsibilities. If broader access is requested, require written justification.

Applications with too many application administrators are prone to inefficiency and gaps.

Limit # of application admins to 2-3 per application, with clear primary and backup designations.


  • SCL: Student & Campus Life
  • SSIT: Student Services Information Technology
  • AAC: Applications Access Controls


  • No labels