Access reviews

Access reviews with a decision on every row

Why quarterly certifications get approved wholesale, and the four changes that stop it.

The review puts employment status next to access, so a person who is Inactive in HR and still holds a licence is flagged before you read a single row. What reaches you is what changed or looks wrong, not the whole estate.

That is a different exercise from the one most teams run. Ask anyone who has run a quarterly access review how many entitlements were revoked. The honest answer is usually close to none.

Not because the access was correct. Because the reviewer got 400 rows of role names with no context and a deadline, and approving all of it was the only option that fit in an afternoon.

Four changes

An Iden access review for Retool under a SOC 2 campaign, 57 pending and 43 done, listing each user with employment status, department, role and groups, with approve and revoke on every row.

A SOC 2 review of one app. Two rows are flagged because the employee is Inactive in HR and still holds access, and three of the rows are not people.

Employment status next to access. 2 rows in that screen are flagged because the person is Inactive in HR and still holds access. That is not a finding somebody hunts for, it is a column.

Capabilities, not role names. Not SF_ADMIN_PROFILE_2, but: can export the customer list, edit pricing, delete records owned by others. The same entitlement, described so a manager can decide about it.

Last use on every row. Held for 11 months, opened twice. That fact drives more revocations than any amount of policy, because it converts an abstract risk question into a concrete one.

The decision acts. Revoke removes the access, in the review, through whatever the app supports. A review producing decisions nobody executes is worse than no review, because it creates a dated record showing you knew.

Cut the batch down

Anything the system can decide, it decides before the campaign opens. Access matching policy exactly, granted this cycle, used regularly, does not need a human.

What is left is the residue: unusual, unused or unexplained. Typically a tenth of the original list, and every row is there for a visible reason.

The evidence

Scope, reviewer, decision, timestamp, what was revoked, and confirmation it was removed. Mapped to SOC 2 CC6.1 through CC6.3 and ISO 27001 A.9, exportable per control.

What still needs a person

The attestation itself. Most frameworks want a named human saying this access is appropriate, and no amount of automation satisfies that. The work is making that signature mean something.

Frequently asked questions

Days rather than weeks, once the batch is cut down to what needs judgement. The reviewers are the constraint, not the tooling, so the only real lever is giving them fewer and better rows.

Yes. Campaigns scope by app, by population, by risk or by control, so a SOC 2 CC6.1 campaign covers exactly what that control asks for and nothing else.

They belong in the same campaign. Service accounts and agents hold access like anybody else and are usually the oldest grants in the estate.