App Logo
IT ops

Drata access review with Claude: user lists from every tool, as evidence (2026)

Prompt template

For our quarter Drata access review, export users and roles from GitHub, Slack, Notion, Vercel, Cloudflare and Linear, put them in one sheet, and flag anyone who is not on our current team list.

Overview

Every quarter, or every year depending on your controls, a Drata access review asks the same question for each system in scope: who has access, with which role, and should they? Answering it means opening a dozen admin consoles, copying member lists, and lining them up against your team.

Why it's hard

Each tool keeps its members somewhere different: GitHub's People tab, Slack's admin page, Notion's member settings, Vercel's team page, Cloudflare per account. Some load members as you scroll, some split pending invites from active members, and roles mean different things in each. Drata's own connections cover part of the stack; for the rest, the list is yours to produce, by hand, again next period. Reviews slip, and a leaver keeps a GitHub seat for months.

How Reduck does it

Reduck is an MCP server whose scripts run in your own Chrome, signed in as you. For an access review, your agent runs one list script per tool, in parallel, and gets back the same structure every time: email, name, role, status, pending invites. The Reduck team keeps its own compliance in Drata and runs these scripts on its own stack.

A typical review, in one request:

  1. List users and roles runs on GitHub, Notion, Vercel, Cloudflare, Linear, Neon and Supabase, and List members on Slack.
  2. The agent merges them into one sheet, one row per person per tool, and compares it to your current team list.
  3. It flags who should not be there: leavers, unknown accounts, stale invites, admins who no longer need it.
  4. You decide. Remove a member and Deactivate a member apply what you approved, and a second export shows the result.
  5. You attach the consolidated file to the review in Drata.

What your agent does

  • Export members and roles from each tool's admin page, pending invites included
  • Merge them into one access list across your stack
  • Compare it with your team list and flag leavers, unknown accounts and stale invites
  • Remove or deactivate a member when you ask, then export again to confirm
  • Check your own Drata status: which account is signed in, your compliance checks, the policies you have accepted

Manual export or Reduck

Manual export Reduck
Effort per review One console per tool, copy and paste One request
Format Different per tool Same fields everywhere
Pending invites Often missed Listed with members
Proof a leaver is gone Screenshot Export before and after
Next period Start again Same request

Who it's for

  • Startups going through SOC 2 or ISO 27001 with Drata
  • Founders and ops leads who own access reviews without an IT team
  • Security teams with tools that Drata does not connect to

FAQ

For each system in scope, the list of people who have access and their role, checked against who should have it, with a record that someone reviewed it. SOC 2 and ISO 27001 auditors ask for that evidence every period. Reduck produces the lists and the comparison; the review decision stays yours.
For the apps Drata does not connect to, or that your plan does not cover, the user list is yours to provide. Reduck exports it from the tool's own admin page, the same list you would copy by hand, in the same format every time. It is also a quick way to cross-check what an integration reports.
No. The list scripts only read the member pages. Removals are separate scripts that run only when you ask for them, and several of them run as a dry run by default.
The Notion removal records the member list before and after and returns whether the right person left and whether anyone else moved. For the other tools, run the list script again after the removal and keep both exports with your review.
Not yet. Today your agent builds the consolidated file and you attach it in Drata. Scripts to renew evidence and act on Drata tests directly are in progress at Reduck.
Yes. Reduck connects to Claude, ChatGPT, Claude Code, Codex and any other MCP client. You ask in plain words, and the agent runs the list scripts for each tool, in parallel when it can.
In your own Chrome, with the Reduck extension, where you are already signed in as an admin of each tool. No API tokens or new admin accounts to create, and nothing to share with a third party.
No. Reduck is an independent tool. Its Drata scripts read what your own Drata account shows you; the access review exports come from each tool's admin pages, under your own seat.

Similar use cases

Notion Vercel GitHub

Audit team access

Pull every member and role across your stack, then offboard someone with proof nobody else moved.

IT ops
OpenAI Slack Atlassian Vercel Cloudflare Stripe

SaaS invoice collection

Collect every SaaS invoice and receipt each month, from email and from the billing portals that never send a PDF, across about 40 subscriptions, and send them to your bookkeeper.

FinOps

Start building not clicking