Access reviews
Works the periodic entitlement list so access nobody still needs is released, and every decision is written down.
Tools
Okta, Microsoft Entra ID, Jira Service Management, Vanta
Outcomes
Every review decision applied, not just noted • Stale access released within one cycle • Review evidence attached to the audit record • Managers asked once, not per system
Documentation
Instruction-ready detail below
Access reviews tend to start from a spreadsheet nobody updates, so the list of who should have access drifts from the list of who does, and the gap only surfaces when an auditor asks or when someone leaves and the account stays open. This workflow pulls the live entitlements from the identity provider rather than from the previous export, groups them by application and by role so a reviewer sees one decision instead of four hundred rows, and adds the last sign-in date and the manager for each holder. Anything unused for ninety days, or held by someone who has left, is separated out as a removal recommendation with the evidence attached. The campaign then routes to each named reviewer with a deadline, and a removal only happens after a reviewer answers, so nothing is revoked on a hunch. When the cycle closes, the confirmations, the removals and the exceptions are written into one record the compliance file can pull from later. What a human still decides is which access a role genuinely requires, which exceptions are worth keeping, and what happens when a reviewer does not answer before the deadline.