Philippines staffing research · Updated
How long does access removal take after a role change?
Measure verified removal across systems from an attributable role-change event.

Research question: How much time elapses between an authorized role-change event and verified removal of access that the new role no longer requires?
Scope: all eligible role changes during twelve weeks for a fixed inventory of business systems, with systems lacking an account owner retained as reported exclusions.
Methodology: Register the authoritative role-change event, expected entitlements, account IDs, removal requests, system acknowledgments, verification checks, reopenings, and study-end censoring. Calculate elapsed time by system and removal path.
Unit of analysis: one person-system entitlement scheduled for removal after one authorized role change. Stable identifiers keep replies, edits, and repeated checks from inflating the denominator.
Classification: removed and verified, request pending, owner clarification, technical failure, approved exception, account not found, reopened, or unresolved.
Measures: counts and denominators, median and percentile removal time, aged unresolved entitlements, exception frequency, verification failure, and reopening rate. Report raw counts beside proportions and describe missingness.
Validation: A second reviewer compares a stratified sample with the authoritative personnel event and performs a read-only entitlement check using the recorded identity.
Operating boundary: A Philippines-based specialist may collect permitted records and apply the frozen codebook. Named internal owners retain privacy, security, legal, financial, employment, policy, and customer-remedy decisions.
Data handling: Use named accounts, minimum necessary fields, documented retention, and de-identified reporting where practical. Register exclusions before reviewing outcomes.
Inference boundaries: Observed lag describes process performance. It does not prove misuse, individual fault, or security impact.
Limitations: Inventory gaps can omit entitlements, shared accounts resist person-level linkage, timestamps may use different clocks, and verification access may be restricted.
Conclusion: Repair inventory and ownership gaps before using lag as a control-performance claim.