Reasons, Expiry and Revocation
A grant is not just a permission — it is a decision somebody took, and it is recorded as one.
Where to find it
Architect Panel → Security:
- Record Access Roles — the roles grants are made against
Architect Panel → Activity:
- Activity Log — where the grant itself is audited
- Record Read Log — what the granted person then read
What a grant records
- The record and the principal.
- The access level and role label.
- A reason.
- Granted by and granted at.
- An optional expiry.
- A revoked at timestamp.
Always fill in the reason
It is the field that makes an access review possible. A list of grants with no reasons can only be reviewed by asking each grantor what they were thinking, which in practice means the review does not happen and the grants stay forever.
"Covering annual leave for the case owner" or "joint working with adult services" takes seconds to write and makes the decision reviewable a year later by somebody who was not there.
Use expiry as the default
Most access is genuinely temporary — covering leave, a period of joint working, an investigation, an audit. Setting an expiry when you make the grant is the only reliable way to have it removed, because nobody comes back later to take access away.
Access that accumulates and never lapses is how an organisation ends up unable to answer who can see a record. An expiry costs nothing to set and can always be extended.
Revoked, not deleted
Withdrawing access stamps a revocation time rather than removing the row. The grant remains visible as something that existed and ended.
This matters when answering who could see a record during a particular period — a question that arises after a complaint or a leak. A deleted grant makes that question unanswerable, and its absence looks worse than the grant would have.
Reviewing grants
Look periodically for grants with no expiry, grants older than your policy allows, and grants to individuals who have since changed role. On a sensitive datastore this belongs in a routine rather than being done when somebody asks.
Grant and read are different records
A grant says somebody could see the record. Whether they did is in the read log, where that datastore has read auditing enabled. Both are needed to answer the question people usually mean.
Worked example
A manager grants a colleague access to a case for two weeks to cover leave, with the reason recorded. The grant lapses on its own. Three months later a complaint asks who had access that fortnight — the expired grant is still there with its reason and dates, and the read log shows which records were actually opened. Neither answer required anybody's recollection.
Recommendations
- Never leave the reason blank.
- Set an expiry by default and extend if needed.
- Revoke; never delete.
- Review open-ended grants on a schedule.