Repository navigation
Ops Access RIGHTS REVOCATION
Navigation: Home > Operations
Version: 1.5.0
Last Updated: 2026-04-06
Addresses: FIND-028 - Automate Manual Rights Revocations
This document describes the automated rights revocation process for ThemisDB, addressing audit finding FIND-028. The automation ensures timely and consistent revocation of access rights when users change roles, leave the organization, or when access is no longer required.
- Automate rights revocation upon user exit or role change
- Ensure timely access removal (within 1 hour of termination)
- Maintain comprehensive audit trail
- Comply with ISO 27001 A.9.2.6 (Removal of access rights)
- Prevent unauthorized access by former employees
-
User Termination
- HR system integration (HRIS webhook)
- Immediate revocation of all access rights
- Account suspension within 15 minutes
-
Role Change
- New role assigned in IAM system
- Excess permissions automatically removed
- Role transition period: 4 hours
-
Contract Expiration
- Contractor/temporary account expiry
- Automatic deactivation on end date
- 7-day grace period with approval
-
Policy Violation
- Security policy violation detected
- Immediate suspension pending investigation
- Security team notification
-
Prolonged Inactivity
- No login for 90+ days
- Automatic account suspension
- Re-activation requires manager approval
Trigger Event β Validation β Revocation β Audit β Notification β Verification
1. Trigger Detection
- HR system event (termination, role change)
- IAM policy change
- Scheduled inactive account check
- Manual security team action
2. Validation
- Verify trigger authenticity
- Check for exceptions/overrides
- Validate user identity
- Review current access rights
3. Revocation Execution
- Suspend user account
- Revoke authentication tokens
- Disable API keys
- Remove group memberships
- Revoke database permissions
- Archive user data
4. Audit Logging
- Log all revocation actions
- Record timestamp and reason
- Capture before/after state
- Store cryptographically signed audit trail
5. Notification
- Notify security team
- Alert user's manager
- Update compliance dashboard
- Create tracking ticket
6. Verification
- Confirm access disabled
- Verify no active sessions
- Check for orphaned permissions
- Update access review reports
Location: scripts/operations/revoke-access.sh
Usage:
# Revoke single user access
./scripts/operations/revoke-access.sh --user <username>
# Revoke with reason
./scripts/operations/revoke-access.sh --user <username> --reason "User terminated"
# Batch revocation from CSV
./scripts/operations/revoke-access.sh --batch users.csv
# Revoke specific role/group
./scripts/operations/revoke-access.sh --user <username> --role admin
# Dry-run mode (simulation)
./scripts/operations/revoke-access.sh --user <username> --dry-run
# Emergency revocation (bypass approval)
./scripts/operations/revoke-access.sh --user <username> --emergency
# Partial revocation (specific permissions only)
./scripts/operations/revoke-access.sh --user <username> --permissions "db.write,api.admin"Options:
-
--user <username>- Target user account -
--batch <file>- Batch revocation from CSV file -
--role <role>- Revoke specific role only -
--permissions <perms>- Revoke specific permissions (comma-separated) -
--reason <reason>- Revocation reason (required for audit) -
--dry-run- Simulation mode without actual changes -
--emergency- Bypass approval workflow -
--preserve-data- Keep user data (don't archive) -
--schedule <time>- Schedule revocation for future time
File: users.csv
username,reason,revocation_type,preserve_data
john.doe,Terminated,full,false
jane.smith,Role Change,partial,true
bob.jones,Contract Expired,full,falseFields:
-
username- User account identifier -
reason- Revocation reason (for audit) -
revocation_type-fullorpartial -
preserve_data-trueto keep user data,falseto archive
Endpoint: POST /api/v1/webhooks/hr-events
Authentication: Bearer token (configured in config/integrations.yaml)
Event Payload:
{
"event_type": "user_terminated",
"event_id": "evt_123456",
"timestamp": "2026-02-03T14:30:00Z",
"user": {
"username": "john.doe",
"employee_id": "EMP-12345",
"email": "john.doe@example.com",
"termination_date": "2026-02-03",
"termination_reason": "Resignation"
},
"metadata": {
"department": "Engineering",
"manager": "jane.smith",
"last_working_day": "2026-02-03"
}
}Event Types:
-
user_terminated- Employee termination -
user_role_changed- Role/department change -
user_suspended- Account suspension -
contractor_expired- Contract end date reached
# .github/workflows/rights-revocation.yml
name: Rights Revocation Automation
on:
repository_dispatch:
types: [hr_event]
workflow_dispatch:
inputs:
username:
description: 'Username to revoke access'
required: true
reason:
description: 'Revocation reason'
required: true
jobs:
revoke-access:
runs-on: ubuntu-latest
steps:
- name: Checkout
uses: actions/checkout@v3
- name: Execute revocation
run: |
./scripts/operations/revoke-access.sh \
--user ${{ github.event.client_payload.username || github.event.inputs.username }} \
--reason "${{ github.event.client_payload.reason || github.event.inputs.reason }}"
- name: Verify revocation
run: |
./scripts/operations/verify-revocation.sh \
--user ${{ github.event.client_payload.username || github.event.inputs.username }}
- name: Notify stakeholders
run: |
./scripts/operations/notify-revocation.sh \
--user ${{ github.event.client_payload.username || github.event.inputs.username }}Full Revocation:
- β Disable user account
- β Revoke all authentication tokens
- β Terminate active sessions
- β Disable API keys
- β Remove SSH keys
- β Revoke database credentials
- β Remove from all groups/roles
- β Archive user data
- β Notify stakeholders
Partial Revocation (Role Change):
- β Remove excess permissions
- β Update role assignments
- β Maintain required access
- β Update access documentation
- β Notify user and manager
Data Archival:
- User files moved to
archive/users/<username>/ - Retention period: 90 days (configurable)
- Encrypted at rest
- Access restricted to compliance team
Data Preservation (for legal hold):
- Mark account with legal hold flag
- Prevent automated deletion
- Maintain audit trail
- Document preservation reason
Log File: logs/access-revocation-audit.log
Log Format:
{
"event_id": "rev_2026020314301234",
"timestamp": "2026-02-03T14:30:12Z",
"event_type": "access_revoked",
"user": {
"username": "john.doe",
"employee_id": "EMP-12345",
"email": "john.doe@example.com"
},
"revocation": {
"type": "full",
"reason": "User terminated",
"triggered_by": "hr_system_webhook",
"executor": "automation-service",
"actions_taken": [
"account_disabled",
"tokens_revoked",
"sessions_terminated",
"groups_removed",
"data_archived"
]
},
"before_state": {
"account_status": "active",
"roles": ["developer", "db_user"],
"groups": ["engineering", "backend-team"],
"permissions": ["db.read", "db.write", "api.access"]
},
"after_state": {
"account_status": "disabled",
"roles": [],
"groups": [],
"permissions": []
},
"verification": {
"status": "success",
"verified_at": "2026-02-03T14:30:25Z",
"verifier": "automation-service"
}
}-
revocation_triggered- Revocation process started -
validation_completed- Trigger validation finished -
access_revoked- Access rights removed -
account_disabled- Account suspended -
data_archived- User data archived -
verification_completed- Revocation verified -
notification_sent- Stakeholders notified
| Metric | Target | Description |
|---|---|---|
| Time to revoke (termination) | < 15 minutes | From trigger to completion |
| Time to revoke (role change) | < 4 hours | Transition period allowed |
| Verification success rate | 100% | All revocations verified |
| False revocation rate | < 0.1% | Incorrect revocations |
| Audit trail completeness | 100% | All events logged |
Grafana Dashboard: Access Revocation Metrics
Prometheus Metrics:
# Revocation execution time
access_revocation_duration_seconds{type="full"} 45
access_revocation_duration_seconds{type="partial"} 120
# Revocation counts
access_revocations_total{reason="terminated"} 12
access_revocations_total{reason="role_change"} 8
access_revocations_total{reason="inactive"} 3
# Verification status
access_revocation_verification_success_rate 1.0
# Active revocations in progress
access_revocations_in_progress 0
Alerts:
# Alert if revocation takes too long
- alert: SlowRevocation
expr: access_revocation_duration_seconds > 900
for: 1m
annotations:
summary: "Access revocation taking longer than 15 minutes"
# Alert on verification failure
- alert: RevocationVerificationFailed
expr: access_revocation_verification_failed_total > 0
for: 1m
annotations:
summary: "Access revocation verification failed"Contractor Extensions:
# Extend contractor account for 30 days
./scripts/operations/revoke-access.sh --user <username> --extend 30d --reason "Contract extension approved"Temporary Access:
# Grant temporary access (7 days)
./scripts/operations/grant-temporary-access.sh --user <username> --duration 7d --permissions "db.read"Break-glass Scenario:
# Emergency re-activation
./scripts/operations/emergency-access.sh --user <username> --duration 2h --reason "Production incident" --approver <manager>Requirements:
- Manager approval required
- Time-limited access (max 24 hours)
- Enhanced audit logging
- Post-incident review mandatory
A.9.2.6 - Removal or adjustment of access rights
- β Timely removal of access rights on termination
- β Review of access rights on role change
- β Removal of logical access to systems and applications
- β Return/removal of physical access devices
OIS-04 - Segregation of Duties
- β Automated revocation prevents manual errors
- β Separation of revocation and approval
- β Audit trail of all changes
- β Regular verification of revocations
Article 32 - Security of Processing
- β Access controls properly maintained
- β Timely revocation on employee exit
- β Data handling documented
- β Audit logs preserved
# Test revocation with test user
./scripts/operations/revoke-access.sh --user test.user --dry-run
# Verify revocation script
./scripts/operations/test-revocation.sh
# Integration test
./scripts/operations/test-hr-webhook.sh- Account disabled successfully
- All tokens revoked
- Active sessions terminated
- Group memberships removed
- Database permissions revoked
- API keys disabled
- Data archived (if applicable)
- Audit log created
- Notifications sent
- Verification completed
# Restore access (requires manager approval)
./scripts/operations/restore-access.sh --user <username> --approval <ticket-id>
# Restore from backup state
./scripts/operations/restore-access.sh --user <username> --from-backup <timestamp>Rollback Steps:
- Verify revocation was accidental
- Obtain manager/security approval
- Restore account to previous state
- Notify affected user
- Document incident
- Review automation logic
Issue: Revocation script fails
# Check database connectivity
./scripts/operations/revoke-access.sh --check-db
# Verify IAM permissions
./scripts/operations/revoke-access.sh --check-permissionsIssue: Partial revocation incomplete
# Review revocation log
tail -f logs/access-revocation-audit.log
# Verify current user state
./scripts/operations/check-user-access.sh --user <username>
# Complete partial revocation
./scripts/operations/revoke-access.sh --user <username> --forceIssue: HR webhook not triggered
# Test webhook endpoint
curl -X POST https://api.example.com/webhooks/hr-events \
-H "Authorization: Bearer <token>" \
-H "Content-Type: application/json" \
-d '{"event_type": "test"}'
# Check webhook logs
tail -f logs/webhook-events.logConfig File: config/rights-revocation.yaml
rights_revocation:
# Timing settings
timing:
termination_timeout: 900 # 15 minutes
role_change_timeout: 14400 # 4 hours
verification_delay: 60 # 1 minute
# Revocation actions
actions:
disable_account: true
revoke_tokens: true
terminate_sessions: true
remove_groups: true
revoke_db_permissions: true
disable_api_keys: true
archive_data: true
# Data handling
data:
archive_enabled: true
archive_retention_days: 90
encryption_enabled: true
legal_hold_check: true
# Notifications
notifications:
security_team: true
user_manager: true
compliance_team: true
# Integration
integrations:
hr_webhook_enabled: true
iam_sync_enabled: true
audit_logging_enabled: trueDocument Version: 1.5.0
Compliance: ISO 27001 A.9.2.6, BSI C5 OIS-04
Last Reviewed: 2026-02-03
ThemisDB 1.9.0-beta Β· Home Β· Module-Index Β· GitHub Β· Issues
ThemisDB 1.9.0-beta Β· Home Β· Wiki-Index Β· Module-Index Β· FAQ Β· Quick-Reference Β· GitHub Β· Issues Β· Discussions Β· License
- Home
- Hero Articles
- All Wiki Pages
- FAQ
- Edition Comparison
- Repository README
- Changelog
- Roadmap
- Versioning
- Integration Mapping
- Overview
- Readme
- Appendix D Feature Status
- Appendix E Incident Runbooks
- Appendix F AQL Cheatsheet
- Appendix G Configuration
- Appendix H Glossary
- Appendix I Troubleshooting
- Appendix Literatur
- Chapter 00 Genesis
- Chapter 01 Introduction
- Chapter 02 Architecture
- Chapter 03 Multimodel
- Chapter 04 Installation
- Chapter 05 Relational
- Chapter 06 Graph
- Chapter 07 Document
- Chapter 08 Storage Layer
- Chapter 08 Vector
- Chapter 09 Timeseries
- Chapter 10 Enterprise
- Chapter 11 Realtime
- Chapter 12 Computervision
- Chapter 13 Fulltext
- Chapter 14 Geospatial
- Chapter 15 Analytics
- Chapter 16 Ml
- Chapter 16 Sharding
- Chapter 17 LLM Integration
- Chapter 17 Scaling
- Chapter 18 HA
- Chapter 18 Ml
- Chapter 19 Monitoring
- Chapter 19 Monitoring Observability
- Chapter 20 Backup
- Chapter 20 Performance
- Chapter 21 Auth
- Chapter 21 Performance
- Chapter 22 Clients
- Chapter 22 Encryption
- Chapter 23 Testing Qa
- Chapter 24 Ai Ethics
- Chapter 25 Devops Infrastructure
- Chapter 26 Migration Legacy
- Chapter 27 Troubleshooting
- Chapter 28 AQL Reference
- Chapter 29 Analytics Process Mining
- Chapter 30 Deployment Operations
- Chapter 31 API Protocols
- Chapter 32 API Design Rest Principles
- Chapter 32 AQL Oop Implementation
- Chapter 33 Best Practices
- Chapter 34 Query Optimization
- Chapter 35 Data Modeling Patterns
- Chapter 36 Security Hardening
- Chapter 37 Ecosystem Integration
- Chapter 38 Observability Sre
- Chapter 39 Performance Tuning Cookbook
- Chapter 40 Data Governance Compliance
- Chapter 41 Hands On Labs
- Chapter 42 Docs Assistant Usage
- Chapter MVCC Hlc
- Cover
- Cover Book
- Index
- Preface
- Test Links Example
- Batch Operations
- Best Practices
- CRUD Tutorial
- Custom Document Ingestion
- Getting Started Tutorial
- Interactive Examples
- Schema Design
- Video Tutorials
- AQL Reference
- AQL Examples
- AQL Overview
- AQL Feature Roadmap
- AQL Geospatial Guide
- AQL LLM Migration Guide
- AQL API
- AQL Grammar (EBNF)
- AQL Root Overview
- AQL Examples (root)
- API Reference
- API Module README
- OpenAPI Overview
- Client SDK Overview
- SDK Overview
- Operations
- Operations Overview
- Operations Runbook
- Operations Handbook
- ThemisCtl Admin Guide
- Pipeline E2E SOPs
- Docker Overview
- Docker Hub README
- Helm Overview
- Packaging Overview
- Operator Overview
- Security Policy
- Production Hardening Checklist
- Security Hardening Guide
- Encryption Key Management
- Access Control Framework
- Zero Trust Policy
- API Authentication & Authorization
- HSM Production Setup
- PKCS11 Integration
- DSGVO / SOC2 Checklist
- Access Model Runbooks
- Access Model Dashboard
- Maturity Automation Runbook
- Access Review Automation
- Access Model Dashboard
- Access Model Runbooks
- Rights Revocation
- Dr Checklists
- Dr Testing
- Incident Response Playbook
- Incident Response Testing
- GPU Oom Recovery
- Grammar Debugging
- Metrics Scrape Troubleshooting
- Model Swap Procedure
- Quota Tuning
- Subagent Deployment
- Logging Configuration
- Content Model
- Crypto & Keys
- Feature Flags Reference
- Modular Architecture Roadmap
- Modularization Guide
- Module Architecture Index
- PostgreSQL Wire Protocol
- Query Scheduling
- Raft Consensus Design
- Resource Pooling
- Source Directory Guide
- Unified Access Model
- E1 001 Layered Retrieval Design
- E1 002 Ann Abstraction Strategy
- E1 003 Tensor Summary Types
- E1 004 Lora Package Distinction
- E1 005 Model Switch Compatibility
- E1 006 Federated Tensor Summaries
- E2 001 Evaluation Framework Design
- E2 002 Hardware Profile Strategy
- E2 003 Query Planner Routing Model
- E2 004 Approximation Governance Rules
- E2 005 Cross Layer Fallback Confidence Policy
- E3 001 Distributed Tensor Design
- E3 002 Manifest Coordination Strategy
- E3 003 Recovery And Erasure Choice
- E3 004 Tensor Fabric Infrastructure
- Contributing
- Contributing (root)
- Code of Conduct
- Support
- Maintainers
- CTest Guide
- Build Quick Reference
- Developer Wiki Index
- Build / Test / CI
- Module Index
- Branching Strategy
- Release Strategy
- CI Policy Gates Wave C
- Disabled Stub Policy
- Docs PR Policy
- GA Promotion Sign Off
- Github Milestones Setup
- Governance Policies Phase1
- GPU Self Hosted Runner Requirements
- Hardening Phase 1 2 Summary 2026 09 23
- Maturity Claim Verification Checklist
- Maturity Evidence Registry
- Merge Gate Bot Config
- Merge Gate Status Live
- Phase 1 Closure Report
- Phase 1 Infrastructure Deployment
- Phase 1 Infrastructure Deployment Complete
- Phase 3 Baseline Capture
- Phase 3 Refinement Spec
- Phase 4 Sign Off And Closure
- Phase Closure Policy
- Phase Dependency Graph
- Phase3 Enforcement Runbook
- Plugin Submodule Rollback
- PR Version Targeting
- PR Version Targeting Backfill
- Production Ready 2026 Delivery Plan
- Publish Workflow Audit 2026 09 23
- Query Module Status
- Readme
- Release Governance
- Release Promotion Gate Policy
- Release Validation Checklist
- Root Hygiene Policy
- SBOM Approved Versions
- Security Compliance Audit Report 2026 08 10
- Security Module 5671 Evidence Summary
- Sharding P6 Residual Risk Acceptance
- Sourcecode Compliance Governance
- Src Module Documentation Compliance 2026 09 20
- Updates Development Status Sign Off
- Wave C Implementation Complete
- Wave C Implementation Plan
- Wave C Ml Exit Gate Sign Off
- Wave C Policy Gate Evidence
- Wiki Publish Tracking Guide
- Blob Storage
- Cuda
- Ethics Ai
- Exporters
- Huggingface
- Image Analysis
- Importers
- RPC
- Scraper
- Themisdb Ai Watermark Detector
- User Storage Encrypted
- Chimera Architecture
- Chimera Future
- Chimera Readme
- Chimera Roadmap
- Covina Fastapi Ingestion Architecture
- Covina Fastapi Ingestion Future
- Covina Fastapi Ingestion Roadmap
- Vcc Base Architecture
- Vcc Base Future
- Vcc Base Roadmap
- Vcc Clara Ingestion Architecture
- Vcc Clara Ingestion Future
- Vcc Clara Ingestion Roadmap
- Vcc Veritas Architecture
- Vcc Veritas Future
- Vcc Veritas Roadmap
- 01 Hello World
- 02 Todo App
- 03 Contact Manager
- 04 Inventory System
- 05 Time Series Monitor
- 06 Graph Social Network
- 07 Vector Search Documents
- 08 Dms Erp System
- 09 Iot Sensor Network
- 10 Drone Image Analysis
- 11 Blog Wiki
- 12 Expense Tracker
- 13 Recipe Manager
- 14 Ecommerce Catalog
- 15 Event Management
- 16 Kanban Board
- 17 Crm
- 18 Realtime Chat
- 19 Recommendation Engine
- 20 Smart Home
- 21 Coding Platform
- 22 AQL Diagram Tool
- 23 Traveling Salesman
- 24 Moral Philosophy Debates
- API Versioning
- Distributed Sharding
- Feedback Plugins
- Geo
- Gnn
- Image Analysis
- Legal Lora Training
- LLM
- Lora Sync
- Migration
- Nlp
- Performance
- Railway
- Replication
- Rope Visualization
- Sample Product Config
- Security
- Client SDK Overview
- Quickstart
- Sdk Enhancements
- Sdk Implementation Summary
- Test Suite Readme
- Go
- Java
- Javascript
- Php
- Python
- Ruby
- Rust
- Typescript
- 01 Grundlegende Operationen
- 02 AQL Queries
- 03 Graph Daten
- 04 Multimodell Anwendung
- 01 Quickstart Guide
- 02 AQL Referenz Kurzuebersicht
- 03 Datenmodellierung Guide
- 04 Uebungsaufgaben
- 05 Best Practices Guide
- Training Documents
- Training Overview
- 01 Einfuehrung Und Uebersicht
- 02 Datenmodelle Und Architektur
- 03 AQL Abfragesprache
- 04 Installation Und Setup
- 05 Anwendungsbeispiele
- Training Presentations
- Dependencies Readme
- Processmonitor Readme
- Themis.admintools.shared Readme
- Themis.aqlquerybuilder Readme
- Themis.aqlquerybuilder Roadmap
- Themis.auditlogviewer Readme
- Themis.auditlogviewer Roadmap
- Themis.classificationdashboard Readme
- Themis.classificationdashboard Roadmap
- Themis.compliancereports Readme
- Themis.compliancereports Roadmap
- Themis.gisviewer.controlpanel Readme
- Themis.gisviewer.controlpanel Roadmap
- Themis.impactanalysisviewer Readme
- Themis.impactanalysisviewer Roadmap
- Themis.ingestiontool Readme
- Themis.ingestiontool Roadmap
- Themis.keyrotationdashboard Readme
- Themis.keyrotationdashboard Roadmap
- Themis.piimanager Readme
- Themis.piimanager Roadmap
- Themis.retentionmanager Readme
- Themis.retentionmanager Roadmap
- Themis.sagaverifier Readme
- Themis.sagaverifier Roadmap
- Themis.usbadmintool Readme
- Themis.usbadmintool Roadmap
- Architecture Generator Readme
- CI Readme
- CI Roadmap
- Compiler Diagnostics Readme
- Compiler Diagnostics Roadmap
- Completion Readme
- Copilot Ollama Router Readme
- Copilot Ollama Router Roadmap
- Gnn Readme
- Gnn Roadmap
- Rope Visualizer Readme
- Rope Visualizer Roadmap
- Tco Calculator Readme
- Tco Calculator Roadmap
- Tests Readme
- Tests Roadmap
- Themis Config Wx Readme
- Themis Docs Builder Readme
- Wikipedia Ingestion Readme
- Ai Metadata And Provenance
- Build / Test / CI
- Governance And Roadmap
- Developer Wiki Index
- Module Direct Doxygen Check
- Module Doxygen Baseline Summary
- Module Doxygen Batch
- Module Doxygen Coverage Summary
- Module Doxygen Smoke Summary
- Modules And Apis
- Retrieval Direct Doxygen Check
- Soll Ist Gap Summary
- Wiki Delta Report