Services /  GRC

Access Reviews

Least privilege, evidenced quarterly, without a three-week spreadsheet exercise.

The problem

The policy says access is reviewed every quarter. It has been reviewed once, by one person, from a spreadsheet exported the night before the audit. Nobody has ever removed anything as a result, and the contractor who left in March still has a production role.

The method.

01

Enumerate entitlements from the systems themselves

Pull from the identity provider, cloud IAM (roles, policies, service accounts, access keys and their age), source control and CI, the database, the production admin consoles and the customer-facing application's own admin roles. Service accounts, API keys and machine identities are in scope. They usually outnumber the humans and are almost never reviewed.

02

Reconcile against the HR source of truth

Join entitlements to the employee and contractor roster. The immediate output is the list nobody wants to see: leavers with live access, accounts belonging to nobody, admin rights held by people who changed role two years ago, and long-lived keys that have never rotated.

03

Review by owner, in a form they will actually complete

Reviews go to the manager or system owner who can judge the access, scoped to their people and systems, with a default of revoke rather than a default of keep. A campaign that takes a manager fifteen minutes gets completed; one that ships them a 900-row spreadsheet does not.

04

Close the loop on revocation

A review that produces decisions but no revocations is theatre. Every revoke decision is tracked to the ticket that executed it, and the entitlement is re-pulled afterwards to confirm the access is gone. That re-pull is the evidence an auditor wants and the one most companies cannot produce.

05

Fix the upstream cause

Recurring findings mean a broken joiner-mover-leaver process, not a lazy reviewer. Standing access is converted to role-based groups, break-glass and just-in-time elevation replace permanent admin, and offboarding is wired to the IdP so leavers stop appearing in the next campaign at all.

Access reviews are the clearest case of drift: a control that is real for one week a quarter and fiction for the other twelve. The ROC watches entitlements continuously and raises a privilege grant or an unrevoked leaver in days. The review campaign then confirms a state that is already clean.

What is a user access review?

A user access review is a periodic verification that every account and entitlement in a system still belongs to someone who needs it. System or people owners are shown the current access, decide keep or revoke for each entry, and the revocations are executed and verified. ISO 27001 and SOC 2 both require these reviews and, crucially, require evidence that the revocations actually happened.

How often should access reviews be performed?

Quarterly for production, administrative and privileged access; at least annually for everything else. Termination-driven revocation should happen the same day and is not a substitute for a review. In practice, the interval matters less than whether the review results in revocations that can be evidenced. A quarterly review that never removes anything is not a control.

Do access reviews cover service accounts and API keys?

They must. Non-human identities (service accounts, CI tokens, cloud access keys, integration credentials) typically outnumber human accounts and hold broader privileges, and they are the ones auditors increasingly sample. Each needs a named human owner, a justification, and a rotation and expiry record.

Find out how far you have drifted.

A free exposure assessment. We connect to what you already have, and show you what your dashboards are not showing you.

No obligation. Results in 10 business days.