AW-15 — IT Access, Accounts and Service Requests
| Workflow ID | AW-15 |
| Pack owner | IoL Administrative Affairs (decision of 2 September 2026; see Architecture/04_Ownership_Model.md) |
| Family | K — Facilities, IT, data protection, safety |
| Ownership | Slice of MBRU IT. MBRU IT owns the network, identity and email
accounts, institutional systems, the service desk, information security
policy and institutional change management; IoL owns the request, the
role-based access decision for each dataset it controls, the quarterly
access review, same-day revocation notification and the administration
of the systems it runs itself [IoL to confirm] |
| Governing policy | MBRU information security, acceptable use and access control
policies [IoL to confirm]; Dubai Health information
security requirements where systems are shared
[IoL to confirm]; ISO 9001:2015 clause 7.1.3; ISO
21001:2018 clause 7.1.3 |
| Interfaces | AW-07 staff lifecycle; AW-08 adjunct appointments; AW-16 data protection; AW-03 repository access; AW-13 software licences; AW-06 continuity; AW-14 AV faults |
| OBEF touchpoint | None |
| Process owner | ______________ |
| Version | 0.1 draft |
| Effective | |
| Next review |
1. Purpose and scope
Purpose. To ensure that every person working for or with IoL has the system access their role needs on their first day and no more than that, that access is reviewed by the person accountable for the data rather than by the person who administers the list, that access ends on the day the person leaves, and that faults, requests and changes reach MBRU IT through a route that leaves a record.
Scope statement. This procedure manages IoL's part of IT access from the notification of a joiner, role change or leaver to the provisioning, review and revocation of access, together with service requests, incident reporting, software requests and changes to systems IoL administers.
Applies to. Staff, adjuncts, clinical educators,
visiting faculty, contractors and student assistants holding access to
any system on IoL's behalf; the learning management system, assessment
platform, survey platform, student records system, shared drives, the
controlled document repository under AW-03, the simulation and AV
systems, the CRM under AW-22, and any system IoL administers
[IoL to confirm list].
Does not apply to. Learner accounts, which MBRU IT provisions on enrolment through WF-07; institutional information security policy and infrastructure, which are MBRU's; data protection decisions, which are AW-16's and which this procedure executes.
2. Trigger, boundary and interfaces
| Trigger | A joiner, role change or leaver notification from AW-07 or AW-08; the quarterly review date; a fault, request or security concern raised by any user; a software need; a proposed change to a system IoL administers |
| Endpoint | Access matches the role and is confirmed by the data owner; leaver access revoked and confirmed; ticket closed with MBRU IT reference; change recorded and communicated |
| Upstream | AW-07 and AW-08 (who is joining, changing role or leaving, and when); AW-16 (which datasets are restricted and who owns them); AW-03 (who may write to the repository) |
| Downstream | AW-16 (access review evidence, security incidents); AW-13 (licence register); AW-24 (non-conformities from the review); AW-06 (outages affecting continuity) |
| Handoff to the academic pack | None. Academic roles receive access by the same rule as any other role. |
3. Roles and accountability
Process owner. IoL Operations Manager or equivalent
[IoL to confirm].
| Step | Line Manager | Access Coordinator (IoL) | Data Owner | IoL System Administrator | MBRU IT | Process Owner |
|---|---|---|---|---|---|---|
| Request access for a joiner or role change | A/R | R | I | I | I | I |
| Approve access to a dataset or system | I | C | A/R | I | I | I |
| Provision or change access | I | R | I | R | A/R | I |
| Conduct and sign the quarterly access review | C | R | A/R | C | I | I |
| Grant or renew privileged access | C | R | C | I | R | A |
| Notify and confirm revocation on leaving | A/R | R | I | R | R | I |
| Raise a service request or incident | R | R | I | I | A/R | I |
| Approve a software request | C | R | C | I | C | A |
| Approve a change to an IoL-administered system | C | I | C | R | C | A |
[CONTROL] Segregation. The person who approves access does not provision it. The system administrator does not approve their own privileged access. The quarterly review is signed by the data owner, not by the Access Coordinator who maintains the list. Write access to the published area of the controlled document repository is limited to the Document Controller under AW-03 and is never granted for convenience.
4. Procedure
Hold the role-based access matrix. For each system and dataset, the matrix names the data owner, the standard access for each IoL role (none, read, write, administer), and whether the data is restricted under AW-16. The matrix is a controlled register under AW-03 and is the basis for every decision below. [CONTROL] Access outside the standard for a role requires the data owner's written approval with a reason and an expiry date.
Provision on joining. AW-07 or AW-08 notifies the Access Coordinator of the joiner, role, start date and line manager at least 5 working days before the start. The Access Coordinator raises the request to MBRU IT for the identity and email account and to each data owner for system access per the matrix. Access to restricted datasets is not activated until AW-16 induction training is recorded. [CONTROL] No access is provisioned without a request traceable to AW-07 or AW-08; a request from the joiner themselves is not sufficient.
Change on role change. A role change is treated as a leaver from the old role and a joiner to the new one; access accumulated in the old role is removed, not carried over.
Grant privileged access sparingly. Administrator rights on IoL-administered systems are held by named individuals, on a separate account from daily use, approved by the process owner, listed in the privileged access register, and reviewed quarterly. Generic or shared administrator accounts are not used. [CONTROL] Privileged access carries an expiry date not exceeding 12 months.
Run the quarterly access review. The Access Coordinator issues each data owner a list of every person with access to their system or dataset, the level held, and the date last used where the system reports it. The data owner confirms, reduces or removes each entry and signs the list. Removals are actioned within 5 working days. [CONTROL] An unsigned review is an open non-conformity reported to AW-24; the review is not complete until every data owner has signed.
Revoke on leaving, the same day. AW-07 or AW-08 notifies the Access Coordinator of the leaving date in advance. On the last working day the Access Coordinator confirms with MBRU IT that the identity account is disabled and with each system administrator that system access is removed, and records the confirmation. Physical access is handled under AW-14 in the same action. [CONTROL] Revocation is confirmed, not assumed; a leaver whose access is found live at the next review is a reportable non-conformity, and a leaver from a role with restricted data access is reported to AW-16 immediately.
Raise service requests and incidents through the service desk. Faults and requests go to the MBRU IT service desk
[IoL to confirm channel]; IoL logs the reference where the issue affects teaching, assessment or a deadline. Suspected security incidents (lost device, phishing, unexpected access, data sent to the wrong recipient) are reported to MBRU IT and the AW-16 process owner immediately, before any local investigation. Outages affecting a session escalate to the process owner and, where relocation is needed, to AW-14.Request software through one route. Software, subscriptions and cloud tools are requested through the Access Coordinator, checked against the licence register held under AW-13, approved by the process owner and purchased through AW-10. Free tools that process personal data require AW-16 review before use. [CONTROL] No software is installed or subscribed to outside this route; licence counts are reconciled to users at the quarterly review.
Manage changes to systems IoL administers. For any configuration, integration or upgrade to a system IoL runs, the system administrator records purpose, affected users, test, rollback plan and communication, and obtains the process owner's approval before implementation. No change touches assessment delivery during an assessment period. Changes to MBRU-owned systems follow MBRU IT's process, with IoL supplying the impact statement.
Report. Quarterly, the Access Coordinator reports review completion, revocation timeliness, privileged accounts and changes made to the process owner and to AW-16.
Exception routes. Urgent cover access: the data owner may approve verbally, with written approval within 1 working day and a 30-day expiry. Emergency change to restore service: the administrator acts and records the change within 1 working day. Leaver notified late: revocation the same day as notification, and the lateness reported to AW-07.
5. Service standards
| Service | Standard |
|---|---|
| Joiner access request submitted | 5 working days before start |
| Standard access active | First working day |
| Non-standard access decision by the data owner | 3 working days |
| Quarterly review issued and signed | Within 20 working days of quarter end |
| Review removals actioned | 5 working days |
| Leaver access revoked and confirmed | Last working day |
| Security incident reported to MBRU IT and AW-16 | Immediately, within 1 hour of discovery |
6. Records, retention and controls
| Record | System | Retention | Owner |
|---|---|---|---|
| Role-based access matrix | Controlled register under AW-03 | Permanent, versioned | Process owner |
| Access requests and approvals | IoL access log or MBRU IT ticketing | 7 years after access ends | Access Coordinator |
| Quarterly review lists, signed | IoL access log | 7 years | Data owner |
| Privileged access register | IoL access log | 7 years | Process owner |
| Revocation confirmations | IoL access log | 7 years after leaving | Access Coordinator |
| Change records for IoL-administered systems | IoL change log | Life of system plus 3 years | System administrator |
Key controls. (1) Every access traces to an AW-07 or AW-08 notification and a data owner approval. (2) The quarterly review is signed by every data owner. (3) Leaver access is revoked and confirmed on the last working day. (4) Privileged access is named, separate and expiring. (5) Repository write access is limited to the Document Controller. (6) No software outside the licence register.
OBEF touchpoint. None.
7. Performance measures
| Dimension | Measure | Target |
|---|---|---|
| Timeliness | Joiners with standard access on the first working day | 95% |
| Timeliness | Leavers revoked and confirmed on the last working day | 100% |
| Compliance | Quarterly reviews signed by every data owner within 20 working days | 100% |
| Compliance | Leaver accounts found live at review | 0 |
| Accuracy | Access entries reduced or removed at review, as a share of entries | Tracked, declining |
| Experience | Staff rating of IT onboarding and service response, periodic pulse | Tracked |
8. Change control
| Date | Version | Change | Reason | Approved by |
|---|---|---|---|---|
| 2026-09-02 | 0.1 | Initial draft | IoL administrative pack | draft, unapproved |