← All glossary terms

Access reviews

Access review completion log

An access review completion log is the immutable record that a review was completed for a period and cadence.

Updated 24 July 2026

What it means

An access review completion log is a dated sign-off record for a completed review. It records who completed the review, the period covered, the cadence, the completion date, the next due date, notes, and snapshot counts. It is different from the row-by-row access decisions: the log proves the review event happened.

Why it matters

Without a completion record, teams often prove access reviews with scattered exports or a message saying the review was done. That makes it hard to reconstruct cadence. A completion log turns the review into a repeatable governance event and gives management a clearer answer to when the last review happened.

How CertPilot uses the term

CertPilot's completion records are immutable once created. They support access review evidence and reporting. CertPilot does not use the completion log to enforce access changes in external systems; it records the sign-off and evidence context for the review.

What to record

  • Reviewer and completion date.
  • Review period and cadence.
  • Next due date and optional note.
  • Snapshot counts for systems, accounts, and decisions reviewed.

What not to assume

  • A completion log does not prove every external system changed correctly.
  • The log should not be editable after sign-off.
  • A completion record without good inputs is weak evidence.