Access reviews
Access review
An access review is a recurring check of who has access to which systems and whether that access still makes sense.
Updated 24 July 2026
What it means
An access review is a structured review of accounts, systems, and permission levels. The reviewer asks whether each person still needs each type of access and records a decision such as keep, change, remove, or no access. A useful access review includes scope, input records, named system owners, explicit decisions, and a completion record.
Why it matters
Accounts become stale when people change roles, leave the company, switch teams, or stop using a system. A recurring access review gives the team a routine for catching those gaps. It also creates evidence that the review was performed, instead of relying on an informal message that says access looked fine.
How CertPilot uses the term
CertPilot supports manual access reviews with a people/accounts register, systems catalog, access matrix, CSV import/export, and completion log. It records review decisions and evidence. It does not connect to directories, read employee activity, or revoke access inside Google Workspace, Microsoft 365, or any other system.
What to record
- Systems in scope and system owner.
- People/accounts included in the review.
- Access level and review decision for each row.
- Completion date, reviewer, cadence, counts, and next due date.
What not to assume
- Recording a removal decision is not the same as removing access in the source system.
- An access review is not employee surveillance.
- A completed review is operational evidence, not certification.