Illustrative · constructed exampleILL / ACCESS / v1
Sign-in policy register
Access changes you can explain.
A sample policy record showing the intended users, test boundary, exceptions and person responsible for the enforcement decision.
Decision supported · Report-only review
Decide whether the pilot evidence supports enforcement, further observation or a revised policy scope.
| Record | What the record covers | Responsibility / action |
|---|---|---|
| Scope | Named pilot group and required applications | Proposed |
| Observe | Report-only results and relevant sign-in logs | Review |
| Recover | Test a separate emergency-access method | Required |
| Enforce | Approve the change and monitor pilot sign-ins | Pending |
Evidence to attach
The delivered record would link the policy export, relevant sign-in events, pilot tests and exception approvals. Report-only results alone do not establish that every access path is safe.
Acceptance & limits
Test user and administrator access, confirm the recovery method, agree exclusions for enforced policies and name the person who can reverse the change.
Method: Microsoft · Report-only mode · Emergency access