The review puts employment status next to access, so a person who is Inactive in HR and still holds a licence is flagged before you read a single row. What reaches you is what changed or looks wrong, not the whole estate.
That is a different exercise from the one most teams run. Ask anyone who has run a quarterly access review how many entitlements were revoked. The honest answer is usually close to none.
Not because the access was correct. Because the reviewer got 400 rows of role names with no context and a deadline, and approving all of it was the only option that fit in an afternoon.
Four changes

A SOC 2 review of one app. Two rows are flagged because the employee is Inactive in HR and still holds access, and three of the rows are not people.
Employment status next to access. 2 rows in that screen are flagged because the person is Inactive in HR and still holds access. That is not a finding somebody hunts for, it is a column.
Capabilities, not role names. Not SF_ADMIN_PROFILE_2, but: can export the customer list, edit pricing, delete records owned by others. The same entitlement, described so a manager can decide about it.
Last use on every row. Held for 11 months, opened twice. That fact drives more revocations than any amount of policy, because it converts an abstract risk question into a concrete one.
The decision acts. Revoke removes the access, in the review, through whatever the app supports. A review producing decisions nobody executes is worse than no review, because it creates a dated record showing you knew.
Cut the batch down
Anything the system can decide, it decides before the campaign opens. Access matching policy exactly, granted this cycle, used regularly, does not need a human.
What is left is the residue: unusual, unused or unexplained. Typically a tenth of the original list, and every row is there for a visible reason.
The evidence
Scope, reviewer, decision, timestamp, what was revoked, and confirmation it was removed. Mapped to SOC 2 CC6.1 through CC6.3 and ISO 27001 A.9, exportable per control.
What still needs a person
The attestation itself. Most frameworks want a named human saying this access is appropriate, and no amount of automation satisfies that. The work is making that signature mean something.