Checklist · 13 items · Updated July 2026

Access Review Checklist

The most-sampled control, done right.

Access reviews are the control auditors sample first and the exception they write most. This checklist is the quarterly procedure, sized so a startup can finish it in a day — and produce the artifact that survives sampling.

01 Scope and pull

  • List in-scope systems: production cloud, identity provider, code repos, databases, admin panels, and anything holding customer data
  • Export the actual user list from each system — from the system itself, never from memory or a stale spreadsheet
  • Include service accounts, API keys, and third-party integrations, not just humans
  • Snapshot the exports with dates — the pull itself is evidence

02 Decide

  • Route each system's list to an owner with real context (the person who knows why access exists)
  • Mark every entry: appropriate / modify / revoke — with a note where it isn't obvious
  • Flag privileged access separately and justify each admin role explicitly
  • Check leavers since last review against every system — offboarding gaps surface here
  • Check role changes: transferred employees accumulating old permissions is the classic finding

03 Execute and record

  • Execute revocations and modifications within your policy's window (commonly 5 business days)
  • Verify execution — a revocation decided but not performed is worse than none, because you documented knowing
  • Assemble the artifact: who reviewed, when, per-user decisions, and completed changes
  • Store it where the auditor will find it filed by quarter, and schedule the next review now

One design principle carries this whole checklist: the artifact is the control. Auditors can’t sample your intentions — they sample the document trail. Build the review so the trail assembles itself as you go, and the quarterly cost drops to hours while the audit cost drops to a file-share. That’s the workflow shape of our people management module, and the first thing our outsourced compliance operators put on rails.

Don't Want to Run This Yourself?

Outsourced Compliance

Outsource compliance operations — frameworks, questionnaires, vendor reviews, and audits — to operators on a continuous platform. Fixed monthly scope.

Book a Call
Frequently Asked
How often do access reviews need to run?

Quarterly is the SOC 2 norm and what most policies promise — which makes quarterly binding. Some programs run privileged-access monthly and general access quarterly; write down whatever you'll actually sustain.

Can access reviews be automated?

The pulls, routing, chasing, and record assembly — yes, and should be. The per-user decision requires a human with context. Automation converts a two-week nag cycle into a day of actual judgment, which is exactly what our people-management module does.

What makes a review fail an audit sample?

No artifact (it happened in Slack), no decisions (a list nobody marked up), no execution (revocations decided, never performed), or a cadence gap — three reviews on record where the policy promised four.