Skip to content

Access Reviews

Access reviews (also known as access certifications or recertifications) are periodic audits of user access rights.

They help organizations ensure that users have appropriate permissions and that unnecessary or risky access is identified and removed.

An access review is a structured process where designated reviewers examine and validate user access to applications, roles, and resources. This is a critical control for:

  • Compliance: Meeting regulatory requirements (SOX, GDPR, ISO 27001)
  • Security: Reducing the attack surface by removing excessive privileges
  • Governance: Ensuring access aligns with business needs
  1. Create a review campaign with a defined scope
  2. Start the review to notify reviewers
  3. Review each assignment and decide to certify or revoke
  4. Complete the review to apply decisions
  5. Track completion and generate audit reports

Access reviews follow a defined lifecycle with four statuses:

StatusDescription
DraftThe review is being configured. Scope and reviewers are defined.
In ProgressThe review is active. Reviewers are making certification decisions.
CompletedAll decisions have been made and applied.
CancelledThe review was stopped before completion. No changes applied.
Draft → In Progress → Completed
Cancelled

When creating a new access review, provide:

FieldDescription
NameA clear, descriptive name for the review (e.g., “Q4 2024 Admin Access Review”)
DescriptionOptional context explaining the purpose or scope
ScopeWhat access will be reviewed (see Scope Types below)

The scope determines which access assignments will be included in the review:

Scope TypeDescription
All assignmentsReview all access across the organization
By roleReview access to specific roles
By applicationReview access within specific applications
By principalReview access for specific users or groups

Choosing an appropriate scope ensures reviewers focus on relevant access and aren’t overwhelmed with irrelevant assignments.

Define who will review each type of access:

Reviewer TypeBest For
ManagerThe user’s direct manager reviews their access
Application OwnerThe owner of each application reviews its users
Role OwnerThe owner of each role reviews its members
Specific UsersNamed individuals review all access in scope

When you start a review:

  1. All in-scope assignments are identified
  2. Reviewers are notified (if notifications are configured)
  3. The review dashboard shows progress metrics
  4. Reviewers can begin making decisions

Once started, the review moves to In Progress status.

For each access assignment, reviewers can:

DecisionEffect
CertifyConfirm the access is appropriate and should continue
RevokeFlag the access for removal
DelegateAssign the decision to another reviewer

Reviewers may also add comments to explain their decisions, which are valuable for audit trails.

While a review is in progress, you can monitor:

  • Completion percentage: How many decisions have been made
  • Pending items: Assignments awaiting review
  • Decisions by type: Breakdown of certify vs. revoke

When you complete a review:

  1. All pending items are marked as reviewed (or flagged for follow-up)
  2. Revocation decisions are queued for execution
  3. The review is locked and marked as Completed
  4. An audit trail is generated

Access flagged for revocation can be:

  • Automatically removed: Integrations remove access in target systems
  • Exported for manual action: IT teams receive a list of changes to apply
  • Held for approval: A secondary approval before changes take effect

If a review needs to be stopped before completion:

  1. Click Cancel on the review
  2. Confirm the cancellation
  3. The review moves to Cancelled status

When cancelled:

  • No revocation decisions are applied
  • Partial progress is preserved for reference
  • The review can be deleted if no longer needed

  • Schedule regular reviews: Quarterly for high-risk access, annually for standard access
  • Define clear ownership: Ensure every application and role has a designated owner
  • Communicate in advance: Notify reviewers before the review starts
  • Start focused: Begin with high-risk access (admin roles, sensitive data)
  • Avoid reviewer fatigue: Don’t overload reviewers with too many assignments
  • Use meaningful groupings: Scope by business unit or risk level
  • Set deadlines: Give reviewers a clear timeline
  • Send reminders: Follow up on pending items
  • Escalate delays: Have a process for unresponsive reviewers
  • Apply changes promptly: Don’t let revocations linger
  • Document exceptions: If access is retained despite concerns, note why
  • Analyze patterns: Look for trends across reviews

After completing a review, generate reports including:

  • Executive summary: High-level metrics and key findings
  • Decision details: Full list of certify/revoke decisions
  • Reviewer activity: Who reviewed what and when
  • Exceptions: Access retained despite policy concerns

Access review reports serve as evidence for auditors:

  • Who had access during the review period
  • Who reviewed and approved that access
  • What changes were made as a result
  • When decisions were made (timestamps)

  1. Navigate to Access Reviews in the Big ACL console
  2. Click “New Review” to create a campaign
  3. Configure the scope and name the review
  4. Add reviewers who will certify access
  5. Start the review when ready
  6. Monitor progress and send reminders as needed
  7. Complete the review and apply revocations