Access reviews
Systems catalog
A systems catalog is a maintained list of tools and platforms used as the backbone for access reviews and ownership context.
Updated 24 July 2026
What it means
A systems catalog is a structured record of the applications, platforms, and systems that matter to a team. It usually records the system name, category, vendor, business owner, technical owner, criticality, lifecycle status, URLs, support contact, recovery notes, last reviewed date, and whether the system is used in access reviews.
Why it matters
Access reviews fail when the systems in scope are unclear. Renewal decisions become harder when no one knows who owns a platform. A systems catalog gives teams a shared backbone for ownership and review context without pretending to be a full CMDB.
How CertPilot uses the term
CertPilot's Systems Catalog supports access reviews and can optionally fill the provider/vendor field in renewals. It is manually maintained. It is not a directory connector, SaaS discovery engine, endpoint monitor, CMDB, or enforced system backbone across every module.
What to record
- System name, category, and vendor/provider.
- Business owner and technical owner.
- Criticality and lifecycle status.
- Whether the system is included in access reviews.
What not to assume
- A systems catalog is not automatic SaaS discovery.
- It does not prove dependency maps like a CMDB.
- It is useful only when owners keep it current.