User Access Reviews for SCADA: Joiner, Mover, Leaver
Ask any operation for its SCADA user list and watch the pause. There is the operator who left in March and still has an active login, the integrator's account from a 2023 commissioning job, the manager carrying engineer rights from two roles ago, and the shared "field" password everyone swears they were going to retire. None of these are exotic failures - they are what happens by default when nobody reviews access. This guide gives you the joiner-mover-leaver discipline, a quarterly review process that actually finishes, fixes for role sprawl and contractor accounts, and the evidence trail that satisfies auditors and insurers.
From the Merobix industrial security hub - every security, compliance & certification guide in one place.
Why Access Reviews Fail in OT - and Why That's Dangerous
In IT, a stale account leaks data. In OT, a stale account can open a valve. That asymmetry should make access reviews more disciplined in industrial operations, but in practice they are usually weaker - because OT access grows out of urgency. A unit is down at 2 AM, so someone gets admin "for now." An integrator needs access for commissioning, so an account appears with no end date. A retiring supervisor's login keeps working because the historian reports run under it and nobody knows what breaks if it dies.
Every one of those accounts is attack surface. Departed-employee credentials are a recurring feature in industrial incidents - CISA's joint advisory on threats to US water and wastewater systems specifically calls out former employees whose credentials remain improperly active - and in the insider threat picture generally - not because ex-employees are villains, but because their credentials outlive their loyalty, their laptops, and their password hygiene. A phished credential belonging to someone who left last year is the perfect intrusion: valid, privileged, and watched by no one. The access review is the control that finds these accounts before someone else does - and it is also, not incidentally, the control that auditors, cyber-insurance questionnaires, and frameworks from IEC 62443 to NERC CIP keep asking about by name.
Joiner, Mover, Leaver: The Lifecycle Behind the Review
Access reviews are the audit; joiner-mover-leaver (JML) is the process being audited. Get the process right and reviews become fast confirmations. Get it wrong and every review is an archaeology dig.
| Stage | What Should Happen | The Common Failure |
|---|---|---|
| Joiner | Named account created from a documented request; least-privilege role for the actual job; site scope limited to assigned facilities; MFA enrolled before first login | "Copy Dave's permissions" - inheriting years of Dave's accumulated access on day one |
| Mover | Access re-baselined to the new role: new permissions granted, old ones removed, sign-off from the new supervisor | Addition without subtraction - the mover keeps everything and gains more; this is where role sprawl is born |
| Leaver | Same-day revocation of platform accounts, active sessions, API keys, VPN, and any shared secrets they knew; access removal on the offboarding checklist next to the truck keys | The account that "we'll get to next week" and still works at the next audit - or the departure nobody told the SCADA admin about at all |
Two details make the leaver step real rather than aspirational. First, revocation must kill live sessions, not just future logins - a platform with session revocation and a logout-everywhere control ends access now, while a platform that only disables the password ends it whenever the current session happens to expire. Second, revocation must cover non-human access: API keys, report credentials, and integrations created under the leaver's identity. Scoped API keys with a managed lifecycle and explicit revocation make this a checklist item instead of a scavenger hunt.
Role Sprawl: How Permissions Accumulate
Role sprawl is entropy applied to authorization. Granting access has a deadline and a requester; removing it has neither. Run that asymmetry for five years and you get accounts whose permissions describe their careers instead of their jobs.
The structural fixes:
- A small, standard role set. Five or six graded roles - viewer, operator, manager, engineer, admin - cover almost every industrial job. Every bespoke exception is a future review finding. Merobix ships exactly this graded model (viewer, operator, manager, engineer, admin, superadmin) so that "what should this person have?" maps to a job title, not a negotiation.
- Site scoping as a first-class boundary. Role answers "what can they do"; site-level authorization answers "where." A north-field operator does not need the gas plant, and in a well-scoped platform they cannot see it.
- Re-baseline on every move. The mover's new access is built from the new role's template - never from their old account plus additions.
- Time-boxed exceptions. Elevated access for a project gets an expiry date at grant time. If it is still needed later, renewing it is a two-minute request; if it is not, it dies on schedule instead of surviving forever.
Running a Quarterly Review That Actually Finishes
Access reviews die of scope. The fix is a tight, repeatable procedure - the discipline that the account-management controls in NIST SP 800-53 formalize - and for a typical operation this is a half-day, quarterly:
- Export the full account list from the SCADA platform: humans, contractors, service accounts, and API keys, with role, site scope, and last-login timestamp.
- Flag the mechanical findings first. No login in 90 days; accounts for people not on the current employee or contractor roster; expired engagements; API keys with no known owner. This is half your findings in ten minutes.
- Have supervisors certify their own people. The control-room lead reviews operators; engineering reviews engineers. The reviewer must be someone who knows what the person actually does - a security admin cannot certify need-to-know alone.
- Challenge privilege, not just existence. For every admin, engineer, and control-capable account: does the current job require it? "Has not used it in six months" is a strong argument for removal.
- Revoke immediately, in the meeting. Findings queued for later have a way of surviving until the next review. Disable first; anyone who genuinely needs access back will tell you within a day, loudly.
- Record everything: who reviewed, what was found, what changed, dated and signed. This artifact is your audit evidence and next quarter's baseline.
Event-driven reviews sit on top of the calendar: same-day for leavers, at role change for movers, and a full sweep after incidents, acquisitions, or vendor transitions. If this quarterly rhythm feels heavy, note that it is one line item in the broader 30-point OT security self-audit - and the one with the best findings-per-hour ratio.
Contractors, Integrators, and Vendor Accounts
Third-party access breaks every assumption the JML process makes: there is no HR record to trigger offboarding, engagements end fuzzily, and the temptation to share one "integrator" login across a firm is strong. The rules that keep it controlled:
- Named individuals, always. An account for "AcmeControls" tells your audit trail nothing. An account for a named engineer at Acme does.
- Expiry at creation. Every contractor account gets an end date matching the engagement, set the day it is opened. Renewal is cheap; discovery of a live 2023 account is not.
- An internal sponsor. Someone on your side owns each third-party account and answers for it at review time. No sponsor, no account.
- Scope to the job. Site-level authorization earns its keep here: the commissioning contractor sees their facility and nothing else, and read-only unless the work requires writes.
- Revoke at demobilization - the day the work ends, not the day someone remembers. Put it in the project closeout checklist alongside redlines and as-builts.
Competency Checks: Authorization Is More Than Security
In OT, "should this account be able to write this setpoint" has two components: permission (their role allows it) and competency (they are trained and current on that equipment). Most platforms only model the first. The gap matters: an authorized-but-unqualified write is how a well-meaning new hire trips a unit. Merobix models both - control actions can require role and competency checks, high-risk workflows such as permit signing can demand step-up re-authentication at the moment of action, and management-of-change and pre-startup safety review gates can stand between a command and the process where configured. For the full command-path picture - writable-tag allowlists, setpoint bounds, read-back verification - see our remote control security guide. At review time, this adds one question per control-capable account: is the training current? A lapsed competency should suspend control rights as surely as a lapsed engagement suspends a contractor.
What the Platform Must Give You
A quarterly review is only as good as the tooling underneath it. The platform capabilities that turn this article from theory into a half-day task:
- Graded roles with site-level scoping, so least privilege is expressible rather than aspirational.
- An exportable account inventory with roles, scopes, and last-login data - the review's raw material.
- Immediate session revocation and logout-everywhere, so a leaver's access ends in minutes, not at session expiry.
- Scoped API keys with lifecycle and revocation, so non-human access is inventoried and killable.
- MFA on every account - TOTP or FIDO2/passkeys, per the authenticator guidance in NIST SP 800-63B - with brute-force detection and persistent lockout behind it; our SCADA authentication guide covers the full stack.
- Immutable audit records attributing every login, change, and control action to a named account, so review decisions and their enforcement are provable after the fact.
Merobix ships each of these as platform behavior, which is the difference between an access review that takes an afternoon and one that takes a maintenance window. The details live on the security architecture page.
Evidence: What Auditors Actually Want to See
Whether the request comes from a customer audit, an insurer, or a regulator, the ask is the same: prove the reviews happen and prove they bite. That means the dated review artifact - account list, reviewers, findings, actions - plus the platform audit trail showing the revocations landing at specific timestamps, plus the ability to answer "when did this specific person's access end?" with a record instead of a shrug. One practical warning: a review log showing zero findings quarter after quarter reads as a rubber stamp, because healthy reviews almost always catch something. Findings are not embarrassing; they are the review working.
Key takeaway: access reviews are not bureaucracy - they are the scheduled destruction of the accounts an attacker would love most. Run joiner-mover-leaver with same-day leaver revocation, re-baseline movers instead of stacking them, expire contractors at creation, review control-capable accounts quarterly, and keep the evidence. On a platform with graded roles, site scoping, session revocation, and immutable audit records, the whole discipline costs a half-day per quarter. See it working in a live demo.
Frequently Asked Questions
How often should SCADA user access be reviewed?
Quarterly for accounts that can execute control actions or administer the platform, and at least semi-annually for view-only accounts - plus event-driven reviews that do not wait for the calendar: same-day revocation when someone leaves, a role re-baseline when someone changes jobs, and a full review after any incident or vendor transition. Quarterly is the cadence most security frameworks and auditors treat as standard for privileged access, and in OT nearly every operator or engineer account qualifies as privileged.
What is the joiner-mover-leaver process?
Joiner-mover-leaver (JML) is the lifecycle discipline behind access control. Joiners get named accounts with the least privilege their documented job requires, granted through a request that records who approved what. Movers - people changing roles - have access re-baselined to the new role rather than accumulating the old one on top. Leavers have every access revoked the same day: platform accounts, sessions, API keys, VPN, and shared credentials they knew. Access reviews exist to catch what this process missed, and the mover step is where most organizations fail.
How should contractor access to SCADA systems be handled?
Named individual accounts (never a shared integrator login), scoped to the specific sites and roles the engagement requires, with an expiry date set at creation and an internal sponsor accountable for the account. Review contractor accounts on every quarterly cycle with a bias toward disabling anything not actively used, and revoke access the day the engagement ends. In a platform with site-level authorization, scope contractors to only their sites - a commissioning contractor for one facility has no business seeing the rest of the fleet.
What is role sprawl and how do I fix it?
Role sprawl is the slow accumulation of permissions that outlive their reason: the operator who kept admin rights from a project three years ago, the manager with engineer access from a previous role, the temporary grant that became permanent because nobody removed it. It happens because granting access is urgent and removing it never is. The fix is structural: define a small set of standard roles, re-baseline access on every job change instead of adding to it, time-limit exceptional grants, and use quarterly reviews to strip anything the account's current job does not require.
What evidence do auditors want from access reviews?
A dated record for each review cycle showing the account list that was reviewed, who reviewed it, what was found, and what changed - with revocations traceable in the platform's audit trail at specific timestamps. Auditors distrust reviews with zero findings, since healthy reviews almost always catch something. Keep the review artifact (spreadsheet or export, sign-offs, remediation list) alongside the platform's immutable audit records, and be able to demonstrate that a specific leaver's access ended on a specific date.
Sources & Further Reading
- AA21-287A - Ongoing Cyber Threats to U.S. Water and Wastewater Systems (CISA)
- NIST SP 800-53 Rev. 5 - Security and Privacy Controls for Information Systems and Organizations (NIST)
- NIST SP 800-63B - Digital Identity Guidelines: Authentication and Lifecycle Management (NIST)
- ISA/IEC 62443 Series of Standards (International Society of Automation)
- Critical Infrastructure Protection (CIP) Reliability Standards (NERC)
Automation services
Need help turning this into a working system?
Merobix integrates SCADA, programs Allen-Bradley and Siemens PLCs, and designs and fabricates industrial control panels.
Meeting requests are reviewed before confirmation.