Access Reviews
Run periodic access reviews so the right people have the right access — and keep the records auditors ask for.
An access review is a scheduled check of who can get into which systems and roles. During the review, a reviewer looks at each person's access and decides whether it's still appropriate. Running these reviews regularly demonstrates the principle of least privilege and gives you documented proof that access is actively managed.
Running a review
Start the review
Open the review to see who currently has access to which systems and roles, along with the reviewer assigned to check it.
Assess each access
Work through the list and decide on each entry: is this access still needed for the person's job?
Certify, flag, or request removal
Confirm (certify) access that's still appropriate, flag anything that needs a closer look, or request removal of access that's no longer justified.
Complete and record
Finish the review. The completed review is captured as evidence for your audit trail.
How reviews support least privilege
Over time, people change roles and pick up access they no longer need. Regular reviews catch this "access creep" and support your joiners, movers, and leavers process by prompting you to remove access as circumstances change. The result is that everyone holds only the access their role genuinely requires.
Turning findings into action
When a review flags access that should be removed or changed, raise an action so the fix is tracked through to completion. That closes the loop between spotting a problem and resolving it — and shows auditors that findings lead to real remediation.