Identity

A useful access review follows the whole employee lifecycle

Treat access as an ownership and change process, from the first request through role changes and departure.

5 min

Why account lists are not enough

Many organizations begin an access review by exporting a list of accounts. That list is valuable, but it answers only part of the question. A username does not tell you which business process depends on the account, who approved it, whether the access is still needed, or what should happen when the person changes roles. The useful unit of review is the relationship between a person, a responsibility, a system, and an owner.

Start with the services that support important work: email and collaboration, finance, customer support, file storage, cloud administration, and line-of-business applications. The exact list will differ. Include supplier-managed services where the organization still has approval or recovery responsibilities. For each service, name an accountable business owner and a technical contact, even if one person fills both roles.

Follow requests from start to finish

Describe what happens when someone joins. Who requests access? Who approves the business need? Who grants it? Which parts are automatic, and which rely on a message or informal conversation? The goal is not paperwork for its own sake. It is to make sure access matches a current responsibility and someone can explain why it was granted.

Then follow the same person through a role change. A promotion, team move, extended leave, or change of duties may mean adding some permissions and removing others. If the only step is to add access, old privileges can accumulate quietly. Ask whether managers and system owners can identify changes that should trigger a review, and how those changes reach the person who administers the service.

Make departure and recovery responsibilities clear

Departures are a coordination problem across a manager, people operations, IT staff, and service providers. Define how the appropriate people learn that access should change, who confirms completion, and what happens to work files, shared mailboxes, devices, and service accounts. The process should respect the organization’s employment practices and preserve records that must be retained. Avoid relying on one person remembering every disconnected tool.

Recovery deserves the same attention. A service may use multi-step sign-in but still be difficult to recover if its only recovery method belongs to someone who has left. Identify recovery contacts, administrator ownership, and where approved recovery instructions are kept. Sensitive recovery materials should be handled through the organization’s chosen secure process, not copied into a general checklist or public website.

Include suppliers and privileged access

External providers may have access to systems for support, maintenance, or specialized work. Record the provider, business sponsor, purpose, approval path, and how the organization asks for access to be changed or ended. Contracts and technical arrangements vary, so do not assume every supplier can be managed in the same way. Clarify which party performs each step and how a completed change is confirmed.

Administrative roles deserve explicit ownership because they can affect many users or services. Determine which roles are needed, who approves them, how the organization handles changes, and what review cadence is realistic. Use qualified administrators for configuration work. A policy document alone cannot demonstrate that settings are correct; evidence should come from authorized owners and approved administrative records.

Keep the review proportional and repeatable

A first review can focus on the most important systems and the people who can make consequential changes. Record gaps plainly: unknown owner, unclear approval, incomplete account list, or untested recovery route. Give each gap a next step, an owner, and a date to revisit. Do not disguise uncertainty as a passed check.

Repeat the review at a cadence that matches the pace of change and sensitivity of the work. A practical process is better than an elaborate schedule nobody follows. When staff, systems, suppliers, or business responsibilities change, ask whether the access model still fits. That habit makes account management less dependent on memory and gives leaders a clearer view of where more support is needed.

Create a free website with Framer, the website builder loved by startups, designers and agencies.