Access Reviews That Are Not Theatre
The standard review sends managers a list they approve without reading. Three changes make the exercise produce actual removals.
Procedure · 711 words
Periodic access certification is a common compliance requirement and a common waste of everyone's time. The failure mode is predictable and avoidable.
Why the standard version fails
The list is too long. A manager sent two hundred entitlements approves all of them in one click.
The entitlements are unreadable. Technical role names that mean nothing to the person certifying.
There is no information to decide with. No last-login, no indication of what the access permits.
Approving is one click and questioning is an investigation. The incentives are entirely one-directional.
Nothing happens to the ones nobody approves, because the deadline passes and the campaign closes.
The result is a compliance artefact showing that a review occurred, with a certification rate near a hundred percent and a removal rate near zero.
The three changes
One: include last activity. Every line shows when the person last used that access. A manager seeing "no activity in 8 months" beside a name behaves differently from one seeing a name alone.
Two: make the default removal, not retention. Access not explicitly confirmed is suspended at the deadline, reversibly. This inverts the incentive completely and is the single most effective change available.
Three: shorten the list. Review high-risk access frequently and low-risk access rarely or never. A review covering everything covers nothing.
Scoping by risk
Review quarterly: administrator and privileged access, anything touching regulated data, financial systems, anything granting external sharing.
Review annually: ordinary application access in applications holding meaningful data.
Do not review at all: access that everyone has and that carries no elevated risk. Including it dilutes attention and produces the click-through behaviour.
Write the tiering down and justify it, which is also what a regulator wants to see.
Making the line readable
The person's name and role.
The application, in the name people use for it.
What the access permits, in a sentence, not a role code.
Last activity date.
When it was granted and by whom.
Five columns. A reviewer can process this at a reasonable rate; a technical entitlement dump they cannot process at all.
Running the campaign
Small batches, more often, rather than an annual sweep.
A deadline with a consequence, which is the suspension default.
Escalation to the manager's manager for non-response, which produces responses.
A route to say "I do not know", which is honest and more useful than a false approval.
Record the decisions and the reasoning, which is the evidence.
Measuring whether it worked
Removal rate. A review producing no removals did not review anything. Any real estate has access that should be removed.
Response rate and non-response escalations.
Time to complete.
Removals reversed within thirty days, which indicates the default was too aggressive or the information was inadequate.
Report the removal rate to whoever mandated the review. A certification rate of 100 percent with a removal rate of zero is the number that should prompt a redesign, and it is usually presented as a success.
Writing the review line
The single largest determinant of whether a reviewer engages is whether they can understand the line without asking anyone.
Bad: "J. Smith — FIN_GL_RW_PROD — granted 2021-03-14".
Better: "Jane Smith, Marketing Manager — Finance system: can view and edit the general ledger — granted March 2021 by A. Patel — last used 14 months ago."
The differences: the person's role, what the access permits in plain words, who granted it, and when it was last used.
The last-used field does most of the work. Fourteen months is an answer on its own.
Test the format on someone outside IT before running a campaign. If they cannot decide from the line alone, the campaign will produce approvals rather than decisions.
What to do with non-responses
The response rate determines whether a campaign is a review or a formality, and non-response is the normal failure.
A stated default of suspension, reversible, which converts silence into a safe outcome rather than an unsafe one.
Escalation to the manager's manager at the deadline, which reliably produces responses.
A short list per reviewer, because volume is the main cause of non-response.
A route to answer "I do not know", which is honest and directs the question to someone who does.
Report non-response by reviewer to their leadership, once. It is rarely needed twice.