What are access reviews?
An access review (or user access review) is a periodic check that confirms each person still has only the access they need, and that access is revoked when it isn’t. It is a core control for SOC 2, ISO 27001, and least-privilege programs.
Definition
An access review is a recurring process in which the right owners confirm that each user’s access to systems and data is still appropriate, and revoke or adjust anything that isn’t.
Background
Access tends to accumulate: people change roles, projects end, and permissions granted “just for now” never get removed. Access reviews counter that drift. On a set cadence (often quarterly for sensitive systems), a reviewer looks at who has access to what and decides to keep, modify, or revoke it. This is a standard expectation of SOC 2 and ISO 27001, and it directly supports the principle of least privilege.
Why it matters
Excess access is one of the most common ways a minor incident becomes a major breach. Regular reviews shrink that blast radius, catch orphaned accounts, and give auditors the recertification records they specifically ask for.
Step by step
- Define scope: which systems and data are sensitive enough to review, and how often.
- Snapshot current access: who has what, ideally pulled from the source system.
- Route each user’s access to the right reviewer (usually a manager or system owner).
- For each, decide keep, modify, or revoke, and record the decision.
- Action revocations promptly and keep the completed review as evidence.
- Repeat on the cadence, and tie it into your joiner-mover-leaver process.
Examples
- A quarterly review of admin access to the production database catches a former project member who no longer needs it.
- An offboarding triggers an immediate review and revocation rather than waiting for the next cycle.
Common mistakes
- Rubber-stamping reviews without actually checking whether access is still needed.
- Reviewing on paper but never revoking, so nothing changes.
- Only reviewing on a schedule and skipping reviews at role changes and offboarding.
FAQ
How often should access reviews happen?
It depends on sensitivity. Critical systems are often reviewed quarterly; less sensitive ones less frequently. Role changes and offboarding should also trigger a review.
What do auditors want to see?
Evidence that reviews happen on a defined cadence, that a responsible owner made keep/modify/revoke decisions, and that revocations were actioned.
How do access reviews relate to least privilege?
They are how you enforce it over time. Least privilege sets the goal of minimal access; access reviews catch and correct the drift away from it.
Do this in Keel, not a spreadsheet
Keel is the AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.
Start free