How to run a user access review
- Export users, roles and last-login dates from each in-scope application.
- Flag the risky accounts (this tool does that step).
- Send each manager or system owner their list to confirm keep or revoke.
- Remove access marked revoke, and record the date.
- Keep evidence: the export, the decisions, who approved and the removal proof. Auditors ask for all four.
How often?
Quarterly for privileged and financial systems is common, and at least yearly for everything else. Check your own control framework and auditor's expectations.
Questions
What is a user access review?
A periodic check that each person and system account has only the access their job needs, with a manager or owner confirming each one.
What is segregation of duties?
A control that stops one person holding two conflicting roles, such as creating vendors and approving payments, so no one can commit and hide an error or fraud alone.
Should service accounts and AI agents be reviewed?
Yes. Every non-human account should have a named owner and least-privilege access, and be reviewed like any user.
Is my data uploaded?
No. The review runs in your browser. Nothing is sent to a server.
Last reviewed 27 September 2026.