Skip to main content

FedRAMP 20x: Reconcile Agency Access Records in Your Trust Center

CDS requires an inventory and history of agency users or systems with access, available to FedRAMP on request. It separately requires access logging and at least six months of access summaries. Reconcile permission history with activity while preserving request-specific scope.

Written by Boundera Team|October 10, 2026|3 min read

Main question

How should Class B/C trust centers reconcile FedRAMP 20x agency access records?

An agency account can remain on a permissions list without ever opening a package. Another account may appear in access logs after its permissions have changed. For Class B and C trust-center teams, useful FedRAMP 20x agency access records explain both who could access Certification Data and what access actually occurred.

Keep permissions and activity distinguishable

The Certification Data Sharing rules contain two related requirements. CDS-TRC-AAI says trust centers MUST maintain an inventory and history of federal agency users or systems with access to Certification Data. That information MUST be available to FedRAMP upon request.

CDS-TRC-ACL says trust centers MUST log access to Certification Data and store summaries of access for at least six months. Information about specific parties SHOULD be available upon request by those parties.

An access inventory answers a permission question. Activity logs answer an event question. Use the two together, while preserving the different request audiences and rule strengths. The six-month minimum expressly applies to access summaries; it should not be rewritten as a six-month raw-event retention requirement or assumed to define the inventory's entire retention policy.

Make identity changes explainable

As an implementation practice, connect each agency user or system to an identifiable agency, its access scope and its permission changes. Include machine identities in that design: the inventory requirement expressly covers users or systems. Keep administrative display names separate from durable identifiers so a renamed account remains traceable.

For example, an agency might replace a service account used to retrieve package materials. A useful history connects the old and new identities to the appropriate permissions and change times. Preserve enough context to explain the transition without treating them as one indistinguishable account.

When access is revoked, record the change instead of silently removing all evidence that access existed. This is an engineering recommendation for maintaining understandable history, not a prescribed retention period or an official account-deletion procedure. Our trust-center agency-scope guide explains how agency-use scope differs from the provider's dependency analysis.

Reconcile records before a request arrives

Compare a sample of permission changes against actual access events. Look for events whose identity cannot be matched, active permissions missing from the inventory, and summaries that omit retrieval activity. Assign an owner to explain discrepancies and record the outcome of the investigation.

Test two retrieval scenarios. First, assemble the inventory and history for a FedRAMP request. Second, assemble access information pertaining to a particular requesting party. Use scope checks so the second export does not casually include another party's activity. The rules identify these request audiences; they do not call for public disclosure of agency-access records.

Choose a reconciliation frequency that fits the operating environment and record who owns it. AAI and ACL do not specify a universal reconciliation interval. Keep this maintenance plan separate from the required six-month minimum for stored access summaries and from package-history management.

Track adoption and operating ownership

The CDS page lists optional adoption and initial certification adoption from July 4, 2026, ongoing adoption on January 1, 2027, and grace until the first independent assessment started after January 1, 2027. Those adoption dates are distinct from how long access summaries are retained.

Give one owner responsibility for producing coherent records across identity management and trust-center logging. A practical first check is to select one agency user and one system account, trace their permission history, and retrieve the corresponding access summary. That small exercise can reveal whether a future request will be answerable.

Frequently asked questions

Does the six-month rule apply to raw access events?

CDS-TRC-ACL expressly requires logging access and storing summaries of access for at least six months. Do not rewrite the summary-retention requirement as an identical raw-event requirement.

Who can request the access information?

CDS-TRC-AAI requires the agency-user or system inventory and history to be available to FedRAMP upon request. CDS-TRC-ACL separately says information pertaining to specific parties SHOULD be available upon request by those parties.

Next step

If you want to turn this guidance into an execution plan, the product side handles control mapping, SSP drafting, and evidence collection.

Related articles