Kinetic Gain · Identity & Access
Pillar guide

Access reviews: re-attest access, do not rubber-stamp it

By Kinetic Gain, Identity & Access Last updated

An access review re-attests that the access people already hold is still appropriate, and revokes what is not. It exists to catch the access creep that granting and removal miss. This page goes deep on running one that survives contact with a real reviewer. For granting access, see the entitlement management guide; for removing it, the deprovisioning guide.

An access review scopes existing access by risk, an accountable owner attests keep or revoke with context, and each revoke decision must propagate to a confirmed removal that becomes audit evidence. Scope by risk focused set Attest w/ context keep or revoke Revoke completes propagates for real Evidence who, when, done
A review that holds up: scope by risk so judgment stays possible, attest with real context, confirm the revoke actually completed, and keep the trail as evidence. A decision to revoke is not a revocation.

What an access review actually is

An access review, also called a user access review (UAR) or access recertification, is a periodic check in which an accountable owner confirms that each person's current access is still appropriate for their role and revokes anything that is not. It is a re-attestation of access that already exists, not a mechanism for granting new access (see the entitlement management guide) or for removing access when someone leaves or changes roles (see the deprovisioning guide).

Its job is to close the gap those processes leave behind. Deprovisioning is never perfect, role changes accumulate leftover permissions, and standing access quietly grows over time, so a periodic review exists to catch the access creep that slips through everything else.

Why access reviews fail in practice

Overwhelm the reviewer and you get a signature, not a judgment

Access reviews fail in predictable ways, and almost all of them trace back to overwhelming the reviewer. A big-bang quarterly campaign can drop thousands of line items on a manager at once, and when the volume is that high the rational response is to approve everything, so the review degrades into rubber-stamping that produces a sign-off with no real judgment behind it.

Even a motivated reviewer often lacks the context to decide well. They see an entitlement name but not what it actually grants, whether it was ever used, or why the person has it. The problem compounds when entitlements are named cryptically, for example an opaque group or role code that no business owner can decode. A reviewer cannot attest to access they cannot understand, so the review becomes a formality that satisfies the checkbox while leaving the underlying risk in place.

The compliance and risk drivers

Access reviews are driven by both compliance readiness and the underlying access risk they exist to catch. SOX makes access to financial reporting systems a governance concern, since unreviewed or excessive access to those systems undermines the integrity of financial data. SOC 2 and ISO 27001 both treat periodic review of user access as an expected control, with reviews serving as the evidence that access rights remain aligned to need over time. The point is readiness and a defensible evidence posture, not a claim of being certified or compliant.

Underneath the frameworks sits the real driver: access creep and standing privilege. People accumulate entitlements as roles shift, temporary grants are never withdrawn, and standing privilege no one is watching becomes the exact attack surface an attacker looks for.

The modern approach: risk-based and event-driven

Review the right things at the right time, not everything on a calendar

The modern approach moves away from reviewing everything on a fixed calendar and toward reviewing the right things at the right time. Risk-based scoping is the foundation: review high-risk and privileged access frequently, for example quarterly or continuously, and review low-risk access far less often, so reviewer attention is spent where it matters.

Micro-certifications and event-driven reviews trigger a targeted check at the moment of a role change rather than waiting for the next quarterly cycle, which catches leftover access while the context is still fresh. Delta reviews narrow the surface further by asking the reviewer to look only at what changed since the last attestation, instead of re-reading the full list every time. All of this depends on making entitlements human-readable, so that a reviewer sees plain-language descriptions of what an entitlement grants and can actually judge whether it is still needed. Smaller, contextual, more frequent reviews beat large periodic campaigns precisely because they keep cognitive load low enough to preserve real judgment.

DimensionBig-bang periodic campaignContinuous / event-driven
CadenceFixed calendar, often quarterly or annual, regardless of changeTriggered by risk tier and by real events such as role changes
Reviewer load per sessionHigh, often thousands of line items reviewed at onceLow, small focused sets or only what changed since last time
Rubber-stamp riskHigh, volume pushes reviewers toward approve-allLower, small contextual sets preserve real judgment
Freshness of decisionsStale, access can drift for a full cycle before reviewFresh, access is checked close to when it actually changes
Audit evidence qualityThin, a bulk sign-off with little visible reasoningStronger, per-event decisions with clearer context and trail

Run an access review that is not rubber-stamped

  1. Scope by risk. Filter each review to a focused, high-value set so reviewers see privileged and high-risk access first rather than an undifferentiated wall of entitlements.
  2. Give reviewers readable context. Show what each entitlement actually grants and when it was last used, so the reviewer can judge need instead of guessing at a cryptic name.
  3. Make revoke the easy default and confirm completion. Design the flow so removing access is at least as easy as keeping it, then verify each revocation actually propagated to the target system rather than trusting the decision alone.
  4. Capture the decision trail. Record who reviewed what, when, the decision, and confirmation of completion, so the campaign produces defensible audit evidence, not just a sign-off.
Illustrative scenarioA manager opens a quarterly campaign and is presented with 800 cryptically named entitlements to attest in one sitting. With no description of what each grants and no way to tell which are unused, the reviewer approves them all in a single pass, and the sign-off looks complete while the underlying access creep goes untouched.
Illustrative scenarioAn employee moves from finance into a sales role, and an event-driven micro-certification fires automatically on the role change. The targeted review surfaces financial-system entitlements left over from the previous role, the reviewer revokes them on the spot, and the leftover standing access is gone well before the next audit rather than lingering for a full quarterly cycle.

Producing defensible evidence

A review is only defensible if it produces a durable record: who reviewed what, when they reviewed it, what decision they made, and confirmation that any revocation was actually completed rather than merely decided. The last point is where many programs quietly fail. A reviewer marks an entitlement for removal, the record shows the decision, but the access is never withdrawn in the target system. A decision to revoke is not the same as a revocation.

The removal has to propagate to the systems that enforce it, which is a deprovisioning problem (see the deprovisioning guide), and the evidence trail should tie each revoke decision back to a confirmed completion. Framed as readiness and evidence posture, the goal is a record an auditor can follow end to end, from the accountable owner's attestation through to proof that what should have been removed is gone.

FAQ

What is a user access review (UAR)?
A user access review, also called access recertification, is a periodic check where an accountable owner confirms each person's current access is still appropriate and revokes what is not. It re-attests access that already exists rather than granting or removing access as part of the joiner-mover-leaver flow. Its purpose is to catch access creep and standing privilege that other processes miss.
How often should access reviews happen?
There is no single correct interval. The right cadence depends on risk, so privileged and high-risk access is typically reviewed more often, for example quarterly or continuously, while low-risk access may be reviewed annually. Event-driven reviews at the moment of a role change complement the calendar so leftover access is caught without waiting for the next cycle.
Why do access reviews get rubber-stamped?
Rubber-stamping happens when reviewers are overwhelmed or under-informed. A big-bang campaign that presents thousands of line items at once pushes reviewers toward approving everything, and cryptically named entitlements give them no basis to judge whether access is needed. Reducing the volume per session, scoping by risk, and adding plain-language context are the levers that restore real judgment.
What is the difference between an access review and deprovisioning?
An access review is the periodic re-attestation that existing access is still appropriate, producing a decision to keep or revoke. Deprovisioning is the act of actually removing access, whether triggered by a review, a role change, or a departure. A review that decides to revoke still depends on deprovisioning to carry the removal through to the systems that enforce it, so the two work together but are distinct.