Access reviews

Access reviews with a decision on every row

Why quarterly certifications get approved wholesale, and the four changes that stop it.

The review puts employment status next to access, so a person who is Inactive in HR and still holds a licence is flagged before you read a single row. What reaches you is what changed or looks wrong, not the whole estate.

That is a different exercise from the one most teams run. Ask anyone who has run a quarterly access review how many entitlements were revoked. The honest answer is usually close to none.

Not because the access was correct. Because the reviewer got 400 rows of role names with no context and a deadline, and approving all of it was the only option that fit in an afternoon.

Four changes

Ein Access Review in Iden für Retool im Rahmen einer SOC-2-Kampagne, 57 offen und 43 erledigt, mit Beschäftigungsstatus, Abteilung, Rolle und Gruppen je Nutzer sowie Freigeben und Entziehen in jeder Zeile.

Ein SOC-2-Review für eine Applikation. Zwei Zeilen sind markiert, weil die Person im HR-System inaktiv ist und den Zugriff noch hat. Drei der Zeilen sind keine Personen.

Employment status next to access. 2 rows in that screen are flagged because the person is Inactive in HR and still holds access. That is not a finding somebody hunts for, it is a column.

Capabilities, not role names. Not SF_ADMIN_PROFILE_2, but: can export the customer list, edit pricing, delete records owned by others. The same entitlement, described so a manager can decide about it.

Last use on every row. Held for 11 months, opened twice. That fact drives more revocations than any amount of policy, because it converts an abstract risk question into a concrete one.

The decision acts. Revoke removes the access, in the review, through whatever the app supports. A review producing decisions nobody executes is worse than no review, because it creates a dated record showing you knew.

Cut the batch down

Anything the system can decide, it decides before the campaign opens. Access matching policy exactly, granted this cycle, used regularly, does not need a human.

What is left is the residue: unusual, unused or unexplained. Typically a tenth of the original list, and every row is there for a visible reason.

The evidence

Scope, reviewer, decision, timestamp, what was revoked, and confirmation it was removed. Mapped to SOC 2 CC6.1 through CC6.3 and ISO 27001 A.9, exportable per control.

What still needs a person

The attestation itself. Most frameworks want a named human saying this access is appropriate, and no amount of automation satisfies that. The work is making that signature mean something.

Frequently asked questions

Days rather than weeks, once the batch is cut down to what needs judgement. The reviewers are the constraint, not the tooling, so the only real lever is giving them fewer and better rows.

Yes. Campaigns scope by app, by population, by risk or by control, so a SOC 2 CC6.1 campaign covers exactly what that control asks for and nothing else.

They belong in the same campaign. Service accounts and agents hold access like anybody else and are usually the oldest grants in the estate.