An access review re-attests that the access people already hold is still appropriate, and revokes what is not. It exists to catch the access creep that granting and removal miss. This page goes deep on running one that survives contact with a real reviewer. For granting access, see the entitlement management guide; for removing it, the deprovisioning guide.
An access review, also called a user access review (UAR) or access recertification, is a periodic check in which an accountable owner confirms that each person's current access is still appropriate for their role and revokes anything that is not. It is a re-attestation of access that already exists, not a mechanism for granting new access (see the entitlement management guide) or for removing access when someone leaves or changes roles (see the deprovisioning guide).
Its job is to close the gap those processes leave behind. Deprovisioning is never perfect, role changes accumulate leftover permissions, and standing access quietly grows over time, so a periodic review exists to catch the access creep that slips through everything else.
Access reviews fail in predictable ways, and almost all of them trace back to overwhelming the reviewer. A big-bang quarterly campaign can drop thousands of line items on a manager at once, and when the volume is that high the rational response is to approve everything, so the review degrades into rubber-stamping that produces a sign-off with no real judgment behind it.
Even a motivated reviewer often lacks the context to decide well. They see an entitlement name but not what it actually grants, whether it was ever used, or why the person has it. The problem compounds when entitlements are named cryptically, for example an opaque group or role code that no business owner can decode. A reviewer cannot attest to access they cannot understand, so the review becomes a formality that satisfies the checkbox while leaving the underlying risk in place.
Access reviews are driven by both compliance readiness and the underlying access risk they exist to catch. SOX makes access to financial reporting systems a governance concern, since unreviewed or excessive access to those systems undermines the integrity of financial data. SOC 2 and ISO 27001 both treat periodic review of user access as an expected control, with reviews serving as the evidence that access rights remain aligned to need over time. The point is readiness and a defensible evidence posture, not a claim of being certified or compliant.
Underneath the frameworks sits the real driver: access creep and standing privilege. People accumulate entitlements as roles shift, temporary grants are never withdrawn, and standing privilege no one is watching becomes the exact attack surface an attacker looks for.
The modern approach moves away from reviewing everything on a fixed calendar and toward reviewing the right things at the right time. Risk-based scoping is the foundation: review high-risk and privileged access frequently, for example quarterly or continuously, and review low-risk access far less often, so reviewer attention is spent where it matters.
Micro-certifications and event-driven reviews trigger a targeted check at the moment of a role change rather than waiting for the next quarterly cycle, which catches leftover access while the context is still fresh. Delta reviews narrow the surface further by asking the reviewer to look only at what changed since the last attestation, instead of re-reading the full list every time. All of this depends on making entitlements human-readable, so that a reviewer sees plain-language descriptions of what an entitlement grants and can actually judge whether it is still needed. Smaller, contextual, more frequent reviews beat large periodic campaigns precisely because they keep cognitive load low enough to preserve real judgment.
| Dimension | Big-bang periodic campaign | Continuous / event-driven |
|---|---|---|
| Cadence | Fixed calendar, often quarterly or annual, regardless of change | Triggered by risk tier and by real events such as role changes |
| Reviewer load per session | High, often thousands of line items reviewed at once | Low, small focused sets or only what changed since last time |
| Rubber-stamp risk | High, volume pushes reviewers toward approve-all | Lower, small contextual sets preserve real judgment |
| Freshness of decisions | Stale, access can drift for a full cycle before review | Fresh, access is checked close to when it actually changes |
| Audit evidence quality | Thin, a bulk sign-off with little visible reasoning | Stronger, per-event decisions with clearer context and trail |
A review is only defensible if it produces a durable record: who reviewed what, when they reviewed it, what decision they made, and confirmation that any revocation was actually completed rather than merely decided. The last point is where many programs quietly fail. A reviewer marks an entitlement for removal, the record shows the decision, but the access is never withdrawn in the target system. A decision to revoke is not the same as a revocation.
The removal has to propagate to the systems that enforce it, which is a deprovisioning problem (see the deprovisioning guide), and the evidence trail should tie each revoke decision back to a confirmed completion. Framed as readiness and evidence posture, the goal is a record an auditor can follow end to end, from the accountable owner's attestation through to proof that what should have been removed is gone.
A revoke decision is not a revocation. Make sure removal actually completes.
Deprovisioning guide