Data Integrity

System Access Management

What a definition is not

A definition is SPEQ’s plain-language decode of how a term is used in practice, cited to the documents that define it. It is a practitioner reference, not legal or regulatory advice, it does not replace the definition in the source, and where a regulator’s wording differs the regulator’s wording governs.

The ongoing process of granting, changing, and revoking a user’s access rights to a GxP computerized system in line with their current role, including periodic review of who has access to what, prompt removal of access on role change or departure, and restriction of administrator privileges to those who genuinely need them.

Access management is broader than simply issuing a unique login — it governs what each account is permitted to do once logged in. Role-based access should give each user the minimum privilege needed for their job, so that, for example, a routine operator cannot alter a validated calculation or delete a result, only an authorised administrator can.

Access rights must be kept current: a periodic access review compares who currently has access against who currently needs it, and any gap — a departed employee whose account is still active, or a promoted user whose old permissions were never removed — is itself a data integrity risk.

Administrator or superuser accounts deserve particular scrutiny because they can typically modify configuration, disable audit trails, or change system time — access management procedures should name who holds these rights, why, and how their own use of that access is itself reviewed.

KEY POINTS
  • Governs what an account can do, not only who can log in
  • Role-based access grants the minimum privilege needed for the job
  • Periodic access reviews catch stale or excessive permissions
  • Administrator-level access requires its own justification and oversight
REGULATORY BASIS

PIC/S PI 041-1; MHRA GXP Data Integrity Guidance (2018); EU GMP Annex 11

Frequently asked questions

What is System Access Management?

The ongoing process of granting, changing, and revoking a user’s access rights to a GxP computerized system in line with their current role, including periodic review of who has access to what, prompt removal of access on role change or departure, and restriction of administrator privileges to those who genuinely need them.

Which regulations cover System Access Management?

PIC/S PI 041-1; MHRA GXP Data Integrity Guidance (2018); EU GMP Annex 11