How to Run User Access Reviews Properly (2026)
Security

How to run access reviews auditors will accept

5 min read · Certifyi research team · Updated July 2026

Short answer

An access review must show who reviewed, what they reviewed, when, what decisions they made, and that revocations actually happened. Reviews that are performed but not documented, or documented but not acted on, fail regardless of how thorough the discussion was.

What makes a review defensible

  • A complete user list per in-scope system, exported and dated
  • A reviewer who genuinely knows whether the access is appropriate
  • A recorded decision per user: retain, modify or revoke
  • Evidence that revocations were executed, with dates
  • Sign-off by a named accountable person

Scope: which systems

Start with anything holding production data, customer data or administrative capability.

  • Production infrastructure and cloud consoles
  • Databases and data warehouses
  • Source control and CI/CD
  • Identity provider and privileged groups
  • Customer support tools with data access
  • Finance and HR systems

A quarterly cadence that works

  1. Export current access from each system on a fixed date
  2. Route each list to the manager or system owner, not to a central admin
  3. Require an explicit decision per line rather than blanket approval
  4. Raise tickets for revocations so execution is tracked
  5. Verify closure and attach the evidence to the review record
  6. Store the whole package with the review date

Why reviews fail audits

The usual findings

  • Review performed in a meeting with no record
  • Blanket approval of an entire list with no per-user decision
  • Revocations agreed but never executed
  • Reviewer had no basis to judge appropriateness
  • Service accounts and integrations excluded entirely

Do not forget non-human accounts

Service accounts, API tokens and third-party integrations frequently hold broader access than any employee and are almost never reviewed. Include them, assign each an owner, and check whether the integration is still in use.

Key takeaways

  • Document the reviewer, the decision and the outcome.
  • Route reviews to people who can actually judge appropriateness.
  • Track revocations to completion as evidence.
  • Include service accounts and integrations.

Frequently asked questions

How often should we run them?

Quarterly for production and privileged access is the common expectation. Annually is defensible only for low-risk systems.

Can the IT admin do the review?

They can prepare it, but the decision should come from someone who knows the business need for that access.

What about contractors?

Include them, and review more frequently since engagements end unpredictably.

Is an SSO export enough?

It is a good starting point but misses systems outside SSO and non-human accounts.

Get audit-ready in 8 to 12 weeks

Certifyi pairs the platform with a named compliance lead, at published pricing from $8,000/year.

Book a 20-min deal readiness call

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top