Review product activity and access
Software Trust Manager audit logs record keypair lifecycle changes, certificate issuance, signing activity, release requests and approvals, and administrative actions. Signature logs additionally record individual signing operations.
Account Manager platform audit logs record sign-in activity, user and role changes, and credential changes. Review both platform and product logs when an investigation involves account access and signing activity.
On the cadence required by your agency and whenever responsibilities change:
Confirm that each user and service user with Software Trust Manager access has a current business need.
Review Account Manager and Software Trust Manager role assignments separately.
Review permissions combined through multiple roles, particularly where Manage keypair is granted alongside approval permissions.
Remove roles that are no longer required.
Review integration credentials (API keys, client authentication certificates) for ownership, use, and expiration.
Investigate unexpected keypair, certificate, or release activity, and any keypair export or delete events.