Guest Access Reviewer
pnp/sharepoint-skills
Audits all guest and external user access on the current SharePoint site.
Mailbox and licence register: employee, account type, aliases, groups, tool, licence cost, 2FA and password policy state, and access-review dates.
$ npx skills add sickn33/agentic-awesome-skills --skill company-email-accounts -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install sickn33/agentic-awesome-skills company-email-accounts --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/company-email-accounts .claude/skills/company-email-accounts && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "company-email-accounts" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/company-email-accounts into .claude/skills/company-email-accounts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "company-email-accounts", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/company-email-accountsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add sickn33/agentic-awesome-skills --skill company-email-accounts -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install sickn33/agentic-awesome-skills company-email-accounts --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/company-email-accounts .agents/skills/company-email-accounts && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "company-email-accounts" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/company-email-accounts into .agents/skills/company-email-accounts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "company-email-accounts", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sickn33/agentic-awesome-skills --skill company-email-accounts -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install sickn33/agentic-awesome-skills company-email-accounts --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/company-email-accounts .cursor/skills/company-email-accounts && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "company-email-accounts" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/company-email-accounts into .cursor/skills/company-email-accounts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "company-email-accounts", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/sickn33/agentic-awesome-skills.git --path skills/company-email-accounts--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add sickn33/agentic-awesome-skills --skill company-email-accounts -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install sickn33/agentic-awesome-skills company-email-accounts --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/company-email-accounts .gemini/skills/company-email-accounts && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "company-email-accounts" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/company-email-accounts into .gemini/skills/company-email-accounts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "company-email-accounts", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install sickn33/agentic-awesome-skills company-email-accountsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add sickn33/agentic-awesome-skills --skill company-email-accounts -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/company-email-accounts .github/skills/company-email-accounts && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "company-email-accounts" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/company-email-accounts into .github/skills/company-email-accounts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "company-email-accounts", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sickn33/agentic-awesome-skills --skill company-email-accounts -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install sickn33/agentic-awesome-skills company-email-accounts --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/company-email-accounts .opencode/skills/company-email-accounts && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "company-email-accounts" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/company-email-accounts into .opencode/skills/company-email-accounts/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "company-email-accounts", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
company-email-accountsMailbox and licence register: employee, account type, aliases, groups, tool, licence cost, 2FA and password policy state, and access-review dates.
Company Email Accounts is an agent skill from sickn33/agentic-awesome-skills. Mailbox and licence register: employee, account type, aliases, groups, tool, licence cost, 2FA and password policy state, and access-review dates. Use for account provisioning.
Its SKILL.md is about 5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Documents & Office, covering Access reviews and audit trails. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit b84d35a. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml, csv, sql and markdown).
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
json-schema.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Company Email Accounts loads about 5k tokens when it runs. Until then it costs about 50 tokens; SKILL.md has 1,063 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from sickn33/agentic-awesome-skills at commit b84d35a, republished under its MIT licence (© sickn33). 1,063 words, ~4,998 tokens.
.claude/skills/company-email-accounts/SKILL.md (or your agent's skills folder).What it is: Work email, groups and tool accounts for every person.
Works out the smallest useful Company Email & Accounts setup for the business in front of it, then builds it only when asked. The default output is a short recommendation, not a spreadsheet. Artifacts - CSV, SQL DDL, JSON Schema, Notion mapping - are produced on request, from one field list so they cannot drift apart.
Layer: Layer 3: Onboard. Fits: Starter stage. Table code: n/a.
Also use it when the user says "work email, groups and tool accounts for every person", or describes the same process happening in a spreadsheet, a document or someone inboxes.
Do not use it for: payroll calculation, tax filing, or legal advice. This skill produces empty templates only - it never holds or processes real employee or customer data.
Follow the shared execution contract. The module-specific rules below define only domain fields, decisions, calculations, and safety constraints.
Read the request and pick the intent before asking anything.
Ask only if this is the highest-value missing fact; otherwise proceed without an opener:
Q: Which tools need an account per person?
Skip anything the user already answered, in any earlier message. Ask the rest one at a time, and stop as soon as the remaining answers would not change the output.
Never invent an answer. If the user does not know, record it as unknown and carry on.
Hold the answers in this shape. It stays internal - it is not shown to the user unless they ask, and it never carries a value the user did not give.
module: company-email-accounts
intent: null # setup | advice | review | fix | build | convert | export
scale: null # Starter | Growth | Scale, only if the answer changes it
areas:
"Tools": null
"Accounts": null
"Security": null
"Current process": null
"Outcome": null
requested_outputs: [] # csv | sql | json | notion | xlsx - requested formats only
confirmed_facts: [] # only what the user actually said
open_questions: [] # the unanswered ones, in the order worth askingIf an artifact was requested, build it after resolving essential missing facts. Otherwise give a short recommendation and offer the relevant artifact.
Recommended approach: Build an account register tied to people records, then provision and remove from that one list.
Why this one: Account sprawl is a security problem, not an admin problem. One register per person, with join and leave dates, is the whole fix.
Workflow: Joiner → Create accounts → Assign tools → Leave → Remove access → Log
The one rule that makes this register mean anything: Access Removed Date is empty for as long as the
account is live, and is set on the day access is actually removed. Never pre-fill it with a planned or
probable leaver date, because a removal date that was only a forecast is indistinguishable from one that
happened, and the register is read to answer "does this person still have access". A record that is Active
with a removal date is a contradiction: fix the status or clear the date, never leave both. Closed and
Pending Offboarding must carry the date, or the offboarding is not finished.
Security columns are facts, not targets. Two Factor On, Recovery Email Set and Password Policy Met
record what is true now. They are not a to-do list and must never be pre-set to TRUE to close a ticket. When
one is FALSE, Status may be Active - the account genuinely exists - and the fix is the review, not a
reclassification. Never disable a control in order to make a record look compliant.
Recurring review needs a due date. Last Access Review alone cannot go stale, because it always shows the
most recent review and never says the next one is late. Next Review Due carries the deadline; a review is
overdue when the due date has passed and Last Access Review is still earlier than it. Do not add a Review Frequency field unless the user states one - the cadence is theirs, not this module's to invent.
Once the user asks for it, derive the fields from the confirmed context and emit the requested artifacts. For machine-readable text, keep prose outside the data; for files, provide a usable link. Report material validation failures or limitations separately.
A selected Notion output is rendered by notion-manual-import, so route the
Notion step there. When the user selects Notion, hand that step to
@notion-manual-import: it holds the CSV, the property
mapping, the import steps and the verification checklist, and it renders the Field
Reference below instead of defining a table of its own. Do not restate the mapping
here and do not improvise the import steps. Manual CSV and mapping outputs need no
connection. For requested workspace changes, follow the shared contract: verify actual
tool access and the target before writing. A user saying "connected" is not tool evidence.
Never ask for a Notion password or token.
For an Excel-compatible CSV, use UTF-8 with a byte order mark so Excel opens the
text correctly. A CSV is not an .xlsx workbook; create .xlsx only when the user
requests a workbook.
A CSV carries no types, so after it, name the columns
that need a number, date or currency format applied.
Account Record,Employee Name,Department,Account Type,Work Email,Aliases,Email Groups,Tool or System,Licence Type,Licence Cost,Currency,Created Date,Created By,Two Factor On,Recovery Email Set,Password Policy Met,Last Access Review,Next Review Due,Access Removed Date,Handover To,Status,Notes,Account ID
ACC-EXAMPLE-001,Example Employee,Delivery,Work Email,employee@example.com,"employee, e.surname","all-staff, delivery-team",Example Mail Service,Per User,1200.00,INR,2026-01-15,Example Requester,TRUE,FALSE,FALSE,2026-02-28,2026-02-28,2026-02-28,Example Successor,Closed,Contract ended 2026-02-28. Access removed and mailbox handed to the Example Successor; licences not reassigned.,(blank)
CREATE TABLE company_email_accounts (
account_record VARCHAR(255),
employee_name VARCHAR(255),
department VARCHAR(255),
account_type VARCHAR(100) NOT NULL,
work_email VARCHAR(255),
aliases VARCHAR(255),
email_groups VARCHAR(255),
tool_or_system VARCHAR(255),
licence_type VARCHAR(100) NOT NULL,
licence_cost NUMERIC(14,2) NOT NULL,
currency VARCHAR(255),
created_date DATE NOT NULL,
created_by VARCHAR(255),
two_factor_on BOOLEAN,
recovery_email_set BOOLEAN,
password_policy_met BOOLEAN,
last_access_review DATE,
next_review_due DATE,
access_removed_date DATE NOT NULL,
handover_to VARCHAR(255),
status VARCHAR(100) NOT NULL,
notes TEXT,
account_id SERIAL PRIMARY KEY,
created_at TIMESTAMP DEFAULT NOW(),
updated_at TIMESTAMP DEFAULT NOW(),
CHECK (status IN ('Active', 'Suspended', 'Pending Offboarding', 'Closed')),
-- The core integrity rule: access that has been removed is dated, and live access is not.
CHECK ((status IN ('Closed', 'Pending Offboarding')) = (access_removed_date IS NOT NULL)),
-- A review cannot be recorded after the date it was due.
CHECK (last_access_review IS NULL OR next_review_due IS NULL
OR last_access_review <= next_review_due)
);
CREATE INDEX idx_company_email_accounts_status ON company_email_accounts (status);
```json
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"title": "Company Email Accounts",
"type": "object",
"additionalProperties": false,
"properties": {
"Account Record": { "type": "string" },
"Employee Name": { "type": "string" },
"Department": { "type": "string" },
"Account Type": { "type": "string" },
"Work Email": { "type": "string", "format": "email" },
"Aliases": { "type": "string" },
"Email Groups": { "type": "string" },
"Tool or System": { "type": "string" },
"Licence Type": { "type": "string" },
"Licence Cost": { "type": "number" },
"Currency": { "type": "string" },
"Created Date": { "type": "string", "format": "date" },
"Created By": { "type": "string" },
"Two Factor On": { "type": "boolean" },
"Recovery Email Set": { "type": "boolean" },
"Password Policy Met": { "type": "boolean" },
"Last Access Review": { "type": "string", "format": "date" },
"Next Review Due": { "type": "string", "format": "date" },
"Access Removed Date": { "type": "string", "format": "date" },
"Handover To": { "type": "string" },
"Status": { "type": "string" },
"Notes": { "type": "string" },
"Account ID": { "type": "integer" }
},
"required": [
"Account Type",
"Licence Type",
"Licence Cost",
"Created Date",
"Status"
]
}| CSV column | Notion property | Set after import |
|---|---|---|
| Account Record | Text | Leave as Text. A human-readable reference you choose, not a generated number, so it stays reproducible |
| Employee Name | Title | Use as the database title |
| Department | Text | Leave as Text |
| Account Type | Select | Add options: "Work Email", "Shared Mailbox", "Tool Account", "Group Address" |
| Work Email | Email | Convert to Email |
| Aliases | Text | Leave as Text |
| Email Groups | Text | Leave as Text. Denormalised list, not a Notion Relation: the directory table is not part of this build |
| Tool or System | Text | Leave as Text. Record the vendor the user named, or a generic value if they did not |
| Licence Type | Select | Add options: "Per User", "Per Team", "Shared" |
| Licence Cost | Number (format: currency) | Convert to Number, set format to Currency |
| Currency | Text | Leave as Text. ISO 4217 code, for example INR, not "Rupees" |
| Created Date | Date | Convert to Date |
| Created By | Text | Leave as Text |
| Two Factor On | Checkbox | Convert to Checkbox |
| Recovery Email Set | Checkbox | Convert to Checkbox |
| Password Policy Met | Checkbox | Convert to Checkbox |
| Last Access Review | Date | Convert to Date |
| Next Review Due | Date | Convert to Date. A recurring review needs a due date, otherwise nothing is ever overdue and the cadence cannot be measured |
| Access Removed Date | Date | Convert to Date. Leave EMPTY while the account is live; set it on the day access is actually removed, never as a forecast |
| Handover To | Text | Leave as Text. A person, so a name and not a relation; the directory owns the person record |
| Status | Select | Add options: "Active", "Suspended", "Pending Offboarding", "Closed" |
| Notes | Text | Leave as Text |
| Account ID | Text (preserve source ID) | Keep imported IDs as Text; optionally add a separate Unique ID property |
The rows above are documentation examples only. Emit empty templates unless the user explicitly requests examples. Money stays `currency`, dates stay `date`,
and anything pointing at another table stays `relation`.
## Field Reference
| # | Field | Type | SQL | JSON Schema | Notion | CSV example |
|---:|---|---|---|---|---|---|
| 1 | Account Record | `text` | `VARCHAR(255)` | `string` | Text | `ACC-EXAMPLE-001` |
| 2 | Employee Name | `text` | `VARCHAR(255)` | `string` | Text | `Example Employee` |
| 3 | Department | `text` | `VARCHAR(255)` | `string` | Text | `Delivery` |
| 4 | Account Type | `select` | `VARCHAR(100)` | `string` | Select | `Work Email` |
| 5 | Work Email | `email` | `VARCHAR(255)` | `string, format: email` | Email | `employee@example.com` |
| 6 | Aliases | `text` | `VARCHAR(255)` | `string` | Text | `employee, e.surname` |
| 7 | Email Groups | `text` | `VARCHAR(255)` | `string` | Text | `all-staff, delivery-team` |
| 8 | Tool or System | `text` | `VARCHAR(255)` | `string` | Text | `Example Mail Service` |
| 9 | Licence Type | `select` | `VARCHAR(100)` | `string` | Select | `Per User` |
| 10 | Licence Cost | `currency` | `NUMERIC(14,2)` | `number` | Number (format: currency) | `1200.00` |
| 11 | Currency | `text` | `VARCHAR(255)` | `string` | Text | `INR` |
| 12 | Created Date | `date` | `DATE` | `string, format: date` | Date | `2026-01-15` |
| 13 | Created By | `text` | `VARCHAR(255)` | `string` | Text | `Example Requester` |
| 14 | Two Factor On | `checkbox` | `BOOLEAN` | `boolean` | Checkbox | `TRUE` |
| 15 | Recovery Email Set | `checkbox` | `BOOLEAN` | `boolean` | Checkbox | `FALSE` |
| 16 | Password Policy Met | `checkbox` | `BOOLEAN` | `boolean` | Checkbox | `FALSE` |
| 17 | Last Access Review | `date` | `DATE` | `string, format: date` | Date | `2026-02-28` |
| 18 | Next Review Due | `date` | `DATE` | `string, format: date` | Date | `2026-02-28` |
| 19 | Access Removed Date | `date` | `DATE` | `string, format: date` | Date | `2026-02-28` |
| 20 | Handover To | `text` | `VARCHAR(255)` | `string` | Text | `Example Successor` |
| 21 | Status | `select` | `VARCHAR(100)` | `string` | Select | `Closed` |
| 22 | Notes | `long_text` | `TEXT` | `string` | Text | `Contract ended 2026-02-28. Access removed and mailbox handed to the Example Successor; licences not reassigned.` |
| 23 | Account ID | `id` | `SERIAL PRIMARY KEY` | `integer` | Text (preserve source ID) | (blank) |
## Select Options
**Account Type**
Work Email | Shared Mailbox | Tool Account | Group Address
**Licence Type**
Per User | Per Team | Shared
**Status**
Active | Suspended | Pending Offboarding | Closed
## Relations
Link fields: none
`Email Groups` and `Handover To` are **not** relations. `Email Groups` is a denormalised comma-separated list of
group addresses, and `Handover To` is a person named inline rather than a foreign key. The directory table that
owns people is not part of this build, so no Notion `Relation` is created here and inventing a target database is
forbidden. `Link fields: none` therefore means this table holds no foreign key, not that the register has no
linkage to people - the linkage is by name, and it will drift from the directory.
## Examples
**Prompt**
People leave and their tool logins stay active for months.
**Context first** - one question per message, nothing already answered:
> **Q:** Which tools?
> **A:** Google, Slack and the CRM.
>
> **Q:** Who is admin?
> **A:** One person, no backup.
>
> **Q:** How do you track it?
> **A:** Nowhere.
**Recommended next step** - offered, not built:
> Build an account register tied to people records, then provision and remove from that one list.
>
> Workflow: Joiner → Create accounts → Assign tools → Leave → Remove access → Log
>
> Want the CSV, SQL, JSON Schema and Notion mapping for this?
## Best Practices
- Build when requested; recommend and offer a build for advice-only requests.
- One question per message. A batched intake reads as a form and gets guessed at.
- Keep display names identical across CSV and JSON; document normalized SQL identifiers.
- Use `relation` for anything that points at another table, `text` only for free text.
- Money fields are `currency`, never `text`. Dates are `date`, never free text.
- If the user requests an example row, keep it obviously fake so nobody imports it as real data.
## Limitations
- Empty template only. It does not compute payroll, tax, leave balances or KPIs.
- Notion relations need both databases imported before the link column resolves.
- Select options are a starting set. Rename them to match how the business talks.
- No automation, reminders or sync. Those need the integration layer.
- Does not create or delete accounts. It only records what should exist.
- Legal, tax and HR review is still required before this drives real decisions.
## Security & Safety Notes
- Never fill in real names, salaries, medical or banking data. Placeholders only.
- Label example rows as synthetic, and keep bank details masked.
- Local reads, generation commands, and validation are part of a requested artifact build.
External writes, messages, provisioning, and publication require authorization for that
action and target; existing explicit authorization does not need to be repeated.
- If sensitive data is supplied, avoid repeating unnecessary identifiers. Use only what
the requested review needs; keep generated templates empty. Do not claim deletion
from the conversation or service storage.
- Privacy, legal and disciplinary cases need a qualified human reviewer before anything
is acted on.
## Common Pitfalls
- **Problem:** a static mapping is described as a completed workspace build.
**Solution:** deliver manual mappings without a connection; claim a live change only
after the authorized tool operation succeeds.
- **Problem:** asked all six questions in one message.
**Solution:** ask one, wait, and drop any the first answer already covered.
- **Problem:** built a full system when one table was asked for.
**Solution:** build what was requested; mention the parent skill separately.
- **Problem:** all four artifacts drift apart.
**Solution:** derive all four from the field list in this file, never by hand.
- **Problem:** an account reads `Active` but has an `Access Removed Date`.
**Solution:** one of the two is wrong. Never pre-fill the removal date with a forecast, and fix the pair rather than leaving them to disagree; the SQL CHECK refuses both the contradiction and an undated `Closed` record.
- **Problem:** a review is overdue but nothing is flagged.
**Solution:** `Last Access Review` is a history field and never goes stale on its own. `Next Review Due` is the deadline; compare the two instead of reading the last date as the current state.
- **Problem:** Notion import shows every column as Text.
**Solution:** that is expected. Apply the property mapping table once, after import.
## Related Skills
- [Module Catalog](https://github.com/sickn33/agentic-awesome-skills/blob/main/CATALOG.md) - find the relevant module, then read its skill.
- @people-directory - the employee master record most modules link to.
- @notification-reminder-hub - turns due dates in this module into reminders.
## Reusable Prompt
I want to set up work email, groups and tool accounts for every person for my company. Ask me one short question at a time, and only about what I have not already told you. Then recommend the smallest setup that fits, and wait for me to ask before you build it. When I ask, output CSV, SQL DDL, JSON Schema, a Notion property mapping or an Excel workbook. Data only.
© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/company-email-accounts of sickn33/agentic-awesome-skills.
Open the folder on GitHubat commit b84d35a
We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.
Company Email Accounts next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Company Email Accounts this skillsickn33/agentic-awesome-skills | 47k | 1 repos | ~5k | Automated safety check: Pass | MIT | |
| Guest Access Reviewerpnp/sharepoint-skills | 133 | — | ~2.3k | Automated safety check: Pass | MIT | |
| Permission Reportpnp/sharepoint-skills | 133 | — | ~1.2k | Automated safety check: Pass | MIT | |
| Access Review TriageGRCEngClub/claude-grc-engineering | 419 | — | ~2.4k | Automated safety check: Notes | Custom licence | |
| Performing Access Recertification With Saviyntmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | |
| Building Identity Governance Lifecycle Processmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~7.3k | Automated safety check: Pass | Apache-2.0 |
pnp/sharepoint-skills
Audits all guest and external user access on the current SharePoint site.
pnp/sharepoint-skills
Create a read-only permission and sharing access review report as a self-contained HTML file saved to SharePoint.
GRCEngClub/claude-grc-engineering
Helps you triage a quarterly user access review from an Okta, Azure AD, AWS IAM, GitHub, or generic CSV/JSON export.
mukul975/Anthropic-Cybersecurity-Skills
Configure and execute access recertification campaigns in Saviynt Enterprise Identity Cloud to validate user entitlements, revoke excessive access, and maintain compliance with SOX, SOC 2, and HIPAA.
mukul975/Anthropic-Cybersecurity-Skills
Design identity governance and lifecycle (IGA) programs on platforms like SailPoint, Saviynt, or Entra ID Governance, covering joiner-mover-leaver (JML) automation, role mining, access requests…
mukul975/Anthropic-Cybersecurity-Skills
Designs and runs access review and certification campaigns-scoping, reviewer selection, risk-based prioritization, micro-certification, and remediation tracking-to verify user access matches job…
sickn33/agentic-awesome-skills
Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.
sickn33/agentic-awesome-skills
Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.
sickn33/agentic-awesome-skills
Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.
sickn33/agentic-awesome-skills
Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.
sickn33/agentic-awesome-skills
Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.
sickn33/agentic-awesome-skills
Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.
Categories
Mailbox and licence register: employee, account type, aliases, groups, tool, licence cost, 2FA and password policy state, and access-review dates. Company Email Accounts is an agent skill from sickn33/agentic-awesome-skills. Mailbox and licence register: employee, account type, aliases, groups, tool, licence cost, 2FA and password policy state, and access-review dates.
Company Email Accounts fits situations like: account provisioning; tasks that involve Access reviews and audit trails.
Run `npx skills add sickn33/agentic-awesome-skills --skill company-email-accounts -a claude-code`. Or copy the skill folder (skills/company-email-accounts in sickn33/agentic-awesome-skills) into .claude/skills/company-email-accounts in your project. Claude Code loads it when a task matches its description.
Run `npx skills add sickn33/agentic-awesome-skills --skill company-email-accounts -a codex`. Or copy the skill folder (skills/company-email-accounts in sickn33/agentic-awesome-skills) into .agents/skills/company-email-accounts in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill company-email-accounts -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/company-email-accounts, .gemini/skills/company-email-accounts, .github/skills/company-email-accounts and .opencode/skills/company-email-accounts in your project.
SKILL.md names no scripts, command-line tools or credentials: Company Email Accounts is instructions for the agent only.
SKILL.md names 1 domain. In commands or code: json-schema.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Company Email Accounts is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 5k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Company Email Accounts: Guest Access Reviewer (pnp/sharepoint-skills, 133 stars), Permission Report (pnp/sharepoint-skills, 133 stars), Access Review Triage (GRCEngClub/claude-grc-engineering, 419 stars) and Performing Access Recertification With Saviynt (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,405 GitHub stars. The repository holds 1,497 skills in this directory. The repository was last updated on October 9, 2026.
Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.