Platform module
Access Review Software for Lean IT Teams, MSPs, and Operators
CertPilot gives lean IT teams, MSPs, and operators a clear, repeatable way to review who has access to which systems and produce management-ready evidence. It is a customer-entered register with a Systems Catalog, matrix view, completion sign-off, reminder emails, and an Access Review Register PDF — built for quarterly reviews, not blanket approvals.
See Access Reviews in action
Move from the access matrix to a documented review history.
See how a synthetic workspace brings customer-entered access records, review views, and completion evidence into one preparation workflow.
Synthetic workspace shown. Preparation and evidence organization—not certification, an audit guarantee, or legal advice.
What you can track
The register keeps the practical fields needed for an IT access review process. It is not a directory connector; your team adds records manually or imports them by CSV.
Run quarterly reviews that hold up
A review only counts if it is genuinely performed and provable. CertPilot is shaped to support a repeatable process — not a blanket approval — and to record dated sign-off at the end.
Run on a clear cadence
Set a repeatable schedule — quarterly is the common middle ground — so reviews stay fresh enough to be honest and light enough to actually finish.
Review by exception, not by reflex
The matrix surfaces the access worth questioning — admin rights on a non-admin, a contractor who rolled off, a shared login no one claims — instead of inviting a blanket approve-all.
Right reviewer per system
Record a business owner and a technical owner per system, so a people manager can confirm whether a person still belongs and the system owner can confirm the access level is right.
Close the loop with follow-up
Action-required and overdue states track the access flagged for change until it is resolved in the underlying system — so a review produces decisions, not just a tick.
Matrix view
The matrix is the review-first view. Rows are people, columns are systems, and cells show access levels such as read/view, write/edit, admin/manage, owner, custom values, or no access. It gives reviewers a fast way to see who has access to what — and to review by exception, questioning the access that looks wrong rather than rubber-stamping a blanket approval.
Systems that are no longer in the active catalog remain visible when access records still reference them. CertPilot labels those fallback columns as not in active catalog so old evidence is not hidden or silently removed.
Entries view
Entries view is the audit and detail view. It is where teams add, edit, delete, import, and export individual access records. It is also the place to clean up specific records before completing a review.
Summary tiles
The module summarizes the register with counts for:
Systems Catalog
The Systems Catalog defines the systems that appear as matrix columns and in the Add Entry workflow. It keeps the review shaped around the tools your team actually needs to check.
It is the manual backbone for the review: define each system once — with a business owner and a technical owner, plus optional criticality, lifecycle status, support contact, and recovery notes — and reuse it every cycle. There is no connector sync, so the catalog reflects exactly what your team maintains.
Hide inactive systems from new entries
Mark a system inactive when it should no longer appear in new-entry dropdowns, while still keeping historical records visible in the register and matrix.
Guarded deletion protects evidence
CertPilot blocks catalog deletion when access records still reference that system. Access evidence is never silently deleted just because a catalog definition changes.
Completion Log
After checking the register, a reviewer can complete the review. One completion row is one immutable evidence event for the whole register. It records who completed the review, the completed date, review period, cadence, next review due date, an optional note, and snapshot counts.
This avoids the awkward workflow of marking every row as reviewed just to prove a review happened. The register remains the working data; the completion event is the sign-off evidence.
Reminder status
Access review reminder emails can be enabled from workspace settings. A daily check sends scheduled reminders before upcoming review due dates, so a review is not forgotten and you are not chasing reviewers from scratch.
Reminder delivery is idempotent for the same review due date, so the same due date is not repeatedly emailed. A separate reminder delivery history or log is not exposed yet.
This boundary does not change the access review evidence surface: CertPilot stores customer-entered records and does not inspect access inside Google Workspace, Microsoft 365, or any other private system.
Evidence reports and exports
The Access Review Register PDF is the evidence artifact for the module. It includes access records grouped for review and, when available, the latest completed review summary with completed date, reviewer, review period, cadence, next due date, snapshot counts, and optional note.
CSV import helps teams start from an existing spreadsheet. CSV export keeps the data portable. The PDF is operational evidence for management reviews, client check-ins, and auditor-adjacent requests such as security questionnaires — without claiming certification.
Access review evidence includes
- Customer-entered access records
- Matrix and entries review surfaces
- Latest completed review summary
- CSV import and export
- Access Review Register PDF
Who this is for
CertPilot is for teams that need lightweight user access review evidence but are not ready for a large enterprise IAM, GRC, or audit management platform.
Small IT teams
Keep quarterly access review evidence organized without buying an enterprise IAM or GRC platform.
MSPs
Maintain a clear access review register for clients and bring evidence into service reviews.
Agencies
Track access to client tools, hosting, domains, CMS platforms, and shared operating systems.
Operations teams
Run a lightweight user access review process when ownership is split across managers and vendors.
What CertPilot does not do
The Access Reviews module is deliberately scoped to governance evidence support. That keeps the page honest and keeps sensitive data out of the product.
- No connector sync in this version — access records are customer-entered or CSV-imported, not pulled from Google Workspace, Microsoft 365, or any directory.
- No automatic account discovery or company directory reading.
- No automatic access removal — CertPilot records the decision; the change happens in the underlying system.
- No employee monitoring, activity tracking, or productivity scoring.
- No reading emails, documents, chats, files, AI prompts, or AI responses.
- Operational evidence only — not compliance certification, legal advice, or an audit guarantee.
Build the access review evidence trail before the next quarterly review.
Start with a customer-entered register, review it in the matrix, complete the review, and export the Access Review Register PDF when leadership, a client, or an auditor asks for evidence.
Access reviews FAQ
What is an access review register?
An access review register is a structured record of who has access to which systems, what level of access they have, who reviewed it, what needs action, and when the next review is due.
How often should I run an access review?
Most teams run access reviews quarterly — frequent enough to stay current, light enough to complete every time. CertPilot records each completed review with its date, period, cadence, and next due date, and can email reminders before the next one is due.
Who should sign off the review — the manager or the system owner?
Both contribute. A people manager confirms whether a person still belongs (role, team, employment); a system owner confirms the access level is appropriate. CertPilot records a business owner and a technical owner per system so each question has a named answer, and the completion log captures who signed off.
Can CertPilot connect to Google Workspace or Microsoft 365?
No. CertPilot Access Reviews are customer-entered today. The live module does not connect to Google Workspace, Microsoft 365, HR systems, or identity providers.
Does CertPilot monitor employees?
No. CertPilot stores access records that your team enters or imports. It does not track activity, score productivity, read private content, or inspect how employees work.
What is the difference between the matrix and the review log?
The matrix is the working view for checking who has access to which systems. The review log records completed reviews as immutable evidence events, including reviewer, period, cadence, next due date, notes, and snapshot counts.
Can I export access review evidence?
Yes. CertPilot supports CSV import/export for the register and generates an Access Review Register PDF. The PDF includes the latest completed review summary when one exists.
Does CertPilot send review reminder emails?
Yes. Access review reminder emails can be enabled from workspace settings, and CertPilot can send scheduled reminders before upcoming review due dates. Reminder delivery is idempotent for the same review due date, so the same due date is not repeatedly emailed. A separate reminder delivery history or log UI is not exposed yet.
Is this a compliance certification tool?
No. CertPilot helps produce governance evidence for internal reviews, client evidence, management check-ins, and audit preparation. It does not certify compliance or guarantee an audit outcome.