Overview
Every quarter, or every year depending on your controls, a user access review asks the same question for each system in scope: who has access, with which role, and should they? Answering it means opening a dozen admin consoles, copying member lists, and lining them up against your team.
Why it's hard
Each tool keeps its members somewhere different: GitHub's People tab, Slack's admin page, Notion's member settings, Vercel's team page, Cloudflare per account. Some load members as you scroll, some split pending invites from active members, and roles mean different things in each. Each period, the lists are produced again, by hand. Reviews slip, and a leaver keeps a GitHub seat for months.
How Reduck does it
Reduck is an MCP server whose scripts run in your own Chrome, signed in as you. For an access review, your agent runs one list script per tool, in parallel, and gets back the same structure every time: email, name, role, status, pending invites. The Reduck team runs these scripts on its own stack.
A typical review, in one request:
- List users and roles runs on GitHub, Notion, Vercel, Cloudflare, Linear, Neon and Supabase, and List members on Slack.
- The agent merges them into one sheet, one row per person per tool, and compares it to your current team list.
- It flags who should not be there: leavers, unknown accounts, stale invites, admins who no longer need it.
- You decide. Remove a member and Deactivate a member apply what you approved, and a second export shows the result.
- You keep the consolidated file as the evidence of the review.
What your agent does
- Export members and roles from each tool's admin page, pending invites included
- Merge them into one access list across your stack
- Compare it with your team list and flag leavers, unknown accounts and stale invites
- Remove or deactivate a member when you ask, then export again to confirm
Manual export or Reduck
|
Manual export |
Reduck |
| Effort per review |
One console per tool, copy and paste |
One request |
| Format |
Different per tool |
Same fields everywhere |
| Pending invites |
Often missed |
Listed with members |
| Proof a leaver is gone |
Screenshot |
Export before and after |
| Next period |
Start again |
Same request |
Who it's for
- Startups going through SOC 2 or ISO 27001
- Founders and ops leads who own access reviews without an IT team
- Security teams with tools their compliance platform does not connect to