We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Cybersecurity
  2. Access rights review
Access rights reviews for US businesses

Almost every access review is a rubber stamp, and nobody in the process pretends otherwise.

Hand a manager a list of group names they have no way to interpret and they will approve every line, because the only alternative available to them is guessing. You end up with a completed cycle, a document for the auditor, and precisely no change in who can reach what. Making the review mean something is a design problem rather than a compliance one, and it is the difference between a comfortable SOC 2 audit and writing a management response to a finding.

Book an access review design sessionSee what makes it work
Access rights review and certification for US organizations
  • Approve-allThe outcome nobody admits to
  • Translate itShow consequences, not group names
  • RemovalsThe metric that matters, not completion
  • RecurringA cadence, not a project
What makes a review real

Eight design choices, and the first explains why nearly every review fails.

SOC 2, SOX general controls, HIPAA, NYDFS Part 500, and any NIST-aligned program all require or expect these, and they are performed badly nearly everywhere for one consistent reason: the people asked to certify access are handed information they cannot possibly act on. Everything below is about closing that gap. None of it is about buying a tool.

Translate access into consequences the reviewer understands

A row reading FIN-GL-POST-PROD tells a finance manager nothing at all. Rewrite it as can post journal entries to the live general ledger and they can judge it in two seconds, and they will start taking people off the list. This one change accomplishes more than any platform on the market, and it is the step almost every program skips, because writing the translation is real work and exporting group names takes a minute.

Give it to somebody who actually knows

Whoever reviews has to know what the person does on an average Tuesday, which almost always means their manager rather than IT or the system owner. IT understands what the access is without knowing whether it is warranted. The system owner understands the system without knowing the individual. Sending the review to the wrong person is the second most common design error, and it guarantees blanket approval before anyone opens the file.

Review what matters, not everything

Cover every system and every permission and you produce fatigue, and fatigue produces approval. Cover privileged access, the systems holding regulated or financial data, and anything an outside party can reach, and you get real decisions. Scope it tightly enough that people actually read it. One annual pass over everything is worth less than four quarterly passes over what matters.

Leavers, which is the specific test everyone fails

The recurring review is a safety net, not the control itself. The control is removing access when somebody walks out, evidenced with a timestamp, and this is where auditors get specific. SOC 2 testers sample leavers directly, and the HIPAA Security Rule expects documented termination procedures. Where offboarding works properly, the review finds very little. Where it does not, the review is quietly doing a job that should have been finished months earlier.

Movers, which nobody reviews at all

Somebody moves department, picks up what the new job needs, and keeps everything the old one required, because nothing anywhere triggers a check. This compounds for years unnoticed. Departures get attention because a process fires when someone resigns. Internal moves get nothing. In most companies we assess, the people holding the widest access are the longest-serving, and it is entirely an accident of being promoted repeatedly.

Privileged access, reviewed separately and more often

Administrative access deserves its own cycle rather than being buried inside a general review. The frameworks agree: least privilege and privileged account management run through NIST 800-171 and CMMC, NYDFS Part 500 requires limiting and periodically reviewing access privileges, and shared admin accounts defeat the attribution every framework assumes.

Measure removals, not completion

The number nearly everybody reports is the percentage of reviews completed, which measures whether people clicked a button. The number that tells you whether the control functions is how much access came off. A cycle that hits a hundred percent completion and removes nothing at all is a rubber stamp with excellent statistics, and somebody should say that plainly to whoever receives the report.

Evidence that satisfies whoever asks

SOC 2 auditors, general controls testers, and cyber underwriters all sample these, and they sample individual users rather than reading your policy document. What they want is the review itself, who performed it, when, and what actually changed as a result. A review that happened and left no artifact is indistinguishable from one that never happened.

The uncomfortable part

A review that removes nothing has told you nothing.

Worth confronting head on, because this failure is invisible in every number companies normally report and becomes obvious the instant somebody asks a different question.

  • Pull up the last completed cycle and count the entitlements that came off as a result. If that number is zero, or close to it, across a large population, the review did not do anything. Access genuinely accumulates in every organization, which means a real review always turns something up. A perfectly clean sheet across several hundred users means people approved rather than assessed.
  • None of this is laziness on the reviewers part. They received a list of technical group names, no explanation of what any of it permits, no context about what the person actually does all day, and a due date. Under those conditions approving the lot is the rational choice, because the only alternative is stripping access on a hunch and stopping a colleague from working.
  • The repair belongs on the sending side. Translate every entitlement into what it actually permits, show when it was last used wherever the system will tell you, flag anything unusual for that role, and pre-fill a recommendation the reviewer can accept or override. People engage with that. Nobody can engage with a column of group names.
  • Then measure removals instead of completion. Completion records whether somebody clicked. Removals record whether the control does anything at all. Presenting a completion rate to a board or an audit committee while removals sit at zero is more misleading than presenting no number whatsoever.
Send us your last cycle and we will count the removals for you
How we approach it

Four things that separate a review that works from one that merely finished.

This is design work far more than technical work. Getting the data out of the systems is the easy part. Turning it into something a busy manager will engage with honestly is the hard part.

We write the translation layer, which is where the work really is

Every reviewable entitlement gets mapped to a plain sentence describing what it permits. It is tedious, it takes genuine effort, and skipping it is why most reviews fail, because exporting group names takes minutes and translating them takes days. Once written it is reused every cycle, so the cost lands once and the benefit repeats indefinitely.

We scope down until reviewers will actually read it

A short review people genuinely read beats a comprehensive one that gets approved wholesale, and we will make that argument even when a framework seems to push toward completeness. Privileged access first, then systems holding regulated or financial data, then anything an outsider can reach. The remainder can go annual, or be sampled, or be reasoned about rather than certified line by line.

We report removals, and we tell you when that number is zero

Where a cycle finishes and nothing comes off, you hear that plainly instead of receiving a completion percentage. Access accumulates everywhere, so a genuine review across a real population always finds something. A clean sheet means people approved rather than assessed, and saying so is considerably more useful than a green dashboard.

We close the leaver and mover gaps first, so the net comes up mostly empty

The recurring review is a net, not the control. Where offboarding removes access properly and a role change triggers a check, the review should find very little, and finding very little for that reason is exactly the goal. Where former employees still have access months after leaving, that is the more urgent problem, and we deal with it before designing any review cadence.

Who needs this

Six situations where this stops being optional.

In most of them something outside the company is driving it, which is genuinely helpful, because it gives the review an audience and a date rather than leaving it as an internal good intention.

A company in or approaching a SOC 2 cycle

User access reviews are among the controls SOC 2 auditors sample most consistently, and they sample leavers specifically. A review that runs on a defined cadence, with the reviewer, date, and outcome recorded per item, is the difference between a sampled control and an exception in the report every prospect reads.

A public company or one preparing to be

SOX ITGC testing covers access to the systems supporting financial reporting, and external auditors sample individual users rather than reading policies. The entitlements that matter most, journal posting, vendor master changes, payment release, are exactly the ones a translated review makes reviewable.

A healthcare organization under HIPAA

The Security Rule's administrative safeguards include information access management and workforce termination procedures, and shared clinical logins sit awkwardly against all of it. A designed review, plus a fast evidenced offboarding process, addresses the findings that recur in healthcare environments.

A financial services firm under NYDFS Part 500 or GLBA

NYDFS Part 500 requires covered companies to limit user access privileges and review them periodically, and FTC Safeguards Rule programs expect access controls as part of the written information security program. These are testable expectations, which makes a designed review considerably easier to evidence than an informal one.

A business with high turnover

Restaurants, retail, distribution, and construction, where people arrive and leave constantly and offboarding tends to happen by conversation rather than by process. Here the review is doing real work rather than acting as a net, and the first cycle usually strips out a great deal. The lasting fix is the leaver process rather than running reviews more often, though the review is what finally shows everyone the size of the problem.

A firm answering customer or insurer questions about access control

How access is granted, reviewed, and removed now appears on almost every security questionnaire and insurance application that crosses your desk. Those answers go onto documents somebody signs, which makes accuracy a legal matter rather than a matter of good practice. A review that exists and removes nothing is genuinely hard to describe honestly, and the honest description costs more than fixing the underlying problem would have.

Three kinds of access review

Same activity, three entirely different outcomes.

The middle column describes what most American companies actually run, and it is the costliest of the three, because it burns genuine management hours across the business and changes nothing at all.
Entitlements described in business terms
Designed to be answerable
Rubber stamp
No review at allNot applicable
Reviewer knows the person and their job
Designed to be answerable
Rubber stampSometimes
No review at allNot applicable
Last-used information shown
Designed to be answerable
Rubber stamp
No review at all
Scope narrow enough to be read
Designed to be answerable
Rubber stamp
No review at allNot applicable
Access actually removed as a result
Designed to be answerableRegularly
Rubber stampAlmost never
No review at allNever
Privileged access on its own cycle
Designed to be answerable
Rubber stamp
No review at all
Movers trigger a check
Designed to be answerable
Rubber stamp
No review at all
Management time consumed
Designed to be answerableModerate
Rubber stampModerate
No review at allNone
Survives an auditor asking what changed
Designed to be answerable
Rubber stampAwkwardly
No review at all
Reported metric
Designed to be answerableRemovals
Rubber stampCompletion
No review at allNone
Feature
Designed to be answerable
Rubber stamp
No review at all
Entitlements described in business terms
Not applicable
Reviewer knows the person and their job
SometimesNot applicable
Last-used information shown
Scope narrow enough to be read
Not applicable
Access actually removed as a result
RegularlyAlmost neverNever
Privileged access on its own cycle
Movers trigger a check
Management time consumed
ModerateModerateNone
Survives an auditor asking what changed
Awkwardly
Reported metric
RemovalsCompletionNone
What the reviewer actually sees

The same entitlement, presented two ways.

On the left is what most reviews actually send out. On the right is what makes a manager capable of answering. The underlying access is identical in both columns. Only the presentation changes, and the difference in what comes back is the entire subject of this page.

What is usually sent

FIN-GL-POST-PROD

What the reviewer can act on
Can post journal entries to the live general ledger

What is usually sent

Domain Admins

What the reviewer can act on
Full control of every server, workstation, and account

What is usually sent

HR-SYS-ALLEMP-RW

What the reviewer can act on
Can open and change any employee record, salary included

What is usually sent

SP-SITE-LEGAL-OWNER

What the reviewer can act on
Can manage and share the legal document library externally

What is usually sent

AP-VENDOR-MAINT

What the reviewer can act on
Can change supplier bank details, the invoice fraud path

What is usually sent

Global Reader

What the reviewer can act on
Can read everything in the tenant, including all mailboxes

What is usually sent

CRM-EXPORT-ALL

What the reviewer can act on
Can export the entire customer database to a file

What is usually sent

No usage information

What the reviewer can act on
Last used 14 months ago

What is usually sent

No peer context

What the reviewer can act on
Nobody else in this role has this access

What is usually sent

No recommendation

What the reviewer can act on
Suggested: remove. Accept or override with a reason
What is usually sentWhat the reviewer can act on
FIN-GL-POST-PRODCan post journal entries to the live general ledger
Domain AdminsFull control of every server, workstation, and account
HR-SYS-ALLEMP-RWCan open and change any employee record, salary included
SP-SITE-LEGAL-OWNERCan manage and share the legal document library externally
AP-VENDOR-MAINTCan change supplier bank details, the invoice fraud path
Global ReaderCan read everything in the tenant, including all mailboxes
CRM-EXPORT-ALLCan export the entire customer database to a file
No usage informationLast used 14 months ago
No peer contextNobody else in this role has this access
No recommendationSuggested: remove. Accept or override with a reason
How we set it up

Five steps, with almost all the cost landing in the first cycle.

Writing the translation layer is front-loaded work that repays itself in every cycle after the first. Expect the opening review to be genuine effort and everything after it to be routine.
  1. 1

    Establish what is actually worth reviewing

    Privileged access comes first, then anything holding regulated, personal, or financial data, then anything an outside party can reach. We deliberately cut scope until the population is small enough that reviewers will genuinely read it, because a comprehensive review approved wholesale is worse than a narrow one that gets real attention.

  2. 2

    Build the translation layer

    Each reviewable entitlement gets a plain sentence describing what it allows, a last-used date wherever the system supplies one, and a flag where the entitlement looks unusual for that role. This is the substance of the engagement, and because it is reusable it gets built once and maintained rather than recreated every cycle.

  3. 3

    Fix leavers and movers before the first cycle

    We check the most recent leavers against their removal timestamps and establish whether anything at all fires when somebody changes role. Where former employees still hold access, that is more urgent than any review design, and running a campaign over a population littered with ex-staff squanders the reviewers first impression of the whole process.

  4. 4

    Run the first cycle with support

    Reviewers receive a short briefing, a pre-filled recommendation they can accept or overrule with a reason, and a named person available for questions while the window is open. Removals are then actioned quickly, because nothing teaches somebody to stop caring faster than flagging access for removal and finding it still there next quarter.

  5. 5

    Set the cadence and report removals

    Privileged access runs on a shorter cycle than general access, with the interval set by risk rather than by habit. Reporting to leadership opens with entitlements removed rather than reviews completed, and where a cycle removes nothing we say so and go looking for the reason instead of presenting it as a clean bill of health.

Straight answers

What organizations ask about access reviews.

Because of what lands in their inbox. A column of technical group names, no explanation of what any of it permits, no context about the person, and a due date, leaves approving everything as the only rational move available. The alternative is stripping access on a guess and stopping a colleague from working, which is a considerably worse outcome for the reviewer personally. This is a design failure on the sending side rather than a discipline failure on the receiving side, and treating it as the latter will never fix it.

Count how many entitlements came off as a result of the last cycle. That one figure tells you more than any completion rate ever will. Access accumulates in every company, through role changes, projects, temporary grants nobody unwound, and slow offboarding, so a genuine review across a meaningful population always finds something. Where a cycle covering hundreds of people removed nothing, the reviewers approved rather than assessed, and your completion rate is measuring mouse clicks.

Privileged access more often than general, with the interval driven by risk rather than convention. Plenty of companies land on quarterly for privileged and annual for everything else, which is perfectly sensible, though the right answer depends on your turnover and your regulatory position. Frequency matters far less than whether the review is answerable at all. A quarterly rubber stamp burns four times the management hours of an annual one and produces exactly the same result.

Almost always the line manager, because the question is whether this person needs this access to do their job, and only somebody who knows the job can answer that. IT knows what the access is without knowing whether it is warranted. The system owner knows the system without knowing the person. Sending reviews to IT is common and entirely understandable, and it produces approval by default, because IT has no basis for removing anything and every reason to avoid breaking something.

Somebody changes role, picks up what the new job requires, and keeps everything the old one needed because nothing anywhere triggers a removal. Repeat that across several years and a few promotions and your longest-serving, most trusted people quietly hold the widest access in the company, entirely by accident. Departures get attention because a process fires when someone resigns. Internal moves get none, which is exactly why a recurring review is the only thing that ever catches them.

It depends which apply to you. SOC 2 auditors sample access provisioning, reviews, and leaver removal as a matter of course. SOX ITGC testing covers access to financial reporting systems for public companies. The HIPAA Security Rule expects information access management and documented workforce termination procedures. NYDFS Part 500 requires covered financial services companies to limit user access privileges and review them periodically, and NIST 800-171/CMMC programs carry least privilege and account management controls. We map the specific requirements applying to you rather than generalizing, and your auditor or assessor owns the interpretation.

Not to begin with, and buying one first is a well-trodden way to spend money without fixing anything. A platform automates the campaign, the reminders, and the record, which genuinely helps at scale, and in Microsoft environments Entra access reviews cover a good deal of that with licensing you may already hold. What no platform anywhere will do is decide what your entitlements mean in business terms, and that translation is precisely where reviews succeed or fail. Write the translation first and automate it afterwards if the scale justifies it.

They are usually right, and the answer is to shrink the population rather than escalate to their boss. Ask anyone to certify four hundred lines and no amount of goodwill will produce a considered review. Cut the scope to privileged access, regulated systems, and anything reachable from outside. Pre-fill the recommendations so most lines need only a confirmation. Show last-used dates so the obvious removals leap off the page. Twenty lines that get read are worth more than four hundred that get approved.

They defeat the entire exercise, because there is nobody to certify and no way to attribute anything afterwards. Every framework touching access assumes an action can be traced to a person. The obstacle is almost always operational rather than philosophical, particularly on shared clinical workstations and in shift environments where signing in individually genuinely costs time on every interaction. The answer that works is technical, whether fast reauthentication or badge sign-in, rather than mandating a control that will be worked around inside a week.

Take it off, and make the interesting question how they acquired it rather than the fact that they had it. The answer is nearly always innocent: a project, covering for someone on leave, a role change nobody ever unwound. Occasionally it exposes a provisioning process granting more than was requested, which is worth fixing at the source. Treating individual findings as misconduct rather than as the output of a process makes reviewers reluctant to remove anything next cycle, because nobody wants to get a colleague into trouble.

We can run the whole process remotely: building and maintaining the translation layer, preparing the packs, chasing completion, actioning the removals, and producing the evidence. What we cannot be is the reviewer, because the judgment involved is whether a specific person needs this access for their specific job, and answering that requires knowing both. Any arrangement where an outside party certifies access is a review in name only, and it would not survive the first auditor who asks who made the decision.

Not with a full campaign. Begin with privileged access alone, a small population, properly translated, sent to the right people with recommendations already filled in. That opening cycle proves the mechanics work, produces enough removals to justify the effort, and teaches you what the translation layer actually needs to say before you scale it anywhere. Engagements are scoped per company, driven mostly by how many systems are involved and how much translation the entitlements require. Here is the diagnostic you can run yourself for nothing: open your last completed review and count the entitlements removed as a result.
Test your own review

Fifteen questions about the last access review you ran.

The first set establishes whether the last one was genuine. The second covers the design that decides whether the next one will be. The third looks at the process around it, because this is a safety net and a healthy net catches almost nothing.

Was the last one real

  • How many entitlements were removed as a result?
    The one question worth asking. Zero is not a good result.
  • How long did reviewers spend on it, on average?
    Hundreds of lines cleared in a few minutes means nobody read it.
  • Did any reviewer ask a question during it?
    Not one question across an entire cycle is a warning sign, not a smooth run.
  • Were reviewers shown what each permission actually allows?
    Or a list of technical group names.
  • For any single line, can you name the reviewer, the date, and what happened?
    What a SOC 2 or SOX auditor will sample.

Design of the next one

  • Does whoever reviews actually know what that person does?
    Nearly always the line manager, rather than IT or whoever owns the system.
  • Is it short enough that a busy manager will genuinely read it?
    Privileged, regulated, and externally reachable access first.
  • Can you show last-used dates for entitlements?
    No other column helps a reviewer as much as this one.
  • Does each line arrive with a recommendation they can accept or overrule?
    Turns an open question into a decision.
  • When somebody marks access for removal, does it actually come off?
    Nothing trains a reviewer to disengage faster than a removal that never happens.

The surrounding process

  • Is leaver access removed promptly at exit, with a timestamp?
    Auditors sample your last ten leavers.
  • Does anything trigger a check when somebody changes role?
    Movers are the accumulation nobody reviews.
  • Is privileged access on a separate, more frequent cycle?
    It should not be buried in a general review.
  • Are shared privileged accounts eliminated?
    They defeat attribution, which every framework assumes.
  • Do you report removals to leadership, or completion?
    Completion is the more misleading of the two.
Related reading

The pages around this one.

Entra access reviews

The Microsoft tooling that automates the campaign, the reminders, and the record.

Learn more

Privileged access audit

The one-off assessment of who holds administrative rights and why.

Learn more

Entra ID governance

Lifecycle workflows and entitlement management that keep access matched to roles.

Learn more
Next step

Take your last access review and count the removals.

That single number tells you whether you own a control or an artifact, and finding out costs nothing at all. If it comes back at zero across a large population, the problem is almost certainly what your reviewers received rather than who they are.

Book an access review design sessionSee cybersecurity services

Related Services

Explore more solutions that work great with this service

Zero Trust Architecture Assessment

Your architecture measured against NIST SP 800-207

Learn more

SOC 2 Readiness

Get audit-ready for the report your buyers ask for

Learn more

Microsoft Entra

Identity and access management solutions

Learn more

M365 Tenant Management

Your tenant run properly, end to end

Learn more

Tenant Security Baseline

Documented controls mapped to CIS

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA