Why access drifts
People change roles and keep old permissions, projects end but access remains, contractors leave without their accounts being disabled, and administrators grant broad rights to solve a problem quickly. Without regular reviews, access only grows, and so does the damage a compromised account or an insider can do.
How it works
For each important system, a list of users and permissions is sent to the person who can judge it, usually the system owner or the user's manager. They confirm, adjust or revoke each access, the changes are applied, and the result is recorded with dates and approvals. Privileged accounts are reviewed more often, typically every quarter; other access every six or twelve months, depending on risk.
Making it manageable
Centralising access through SSO and an identity provider reduces the number of places to check. Role based access, part of IAM, means reviewing roles instead of individual permissions. Many identity and compliance platforms automate the review campaigns and keep the evidence.
Where it shows up in compliance
ISO 27001 requires access rights to be reviewed at planned intervals (Annex A 5.18), and SOC 2, the ENS and NIS2 expect the same. Access reviews are among the most requested pieces of evidence in audits, and gaps here are a frequent finding. Privileged access is covered in more depth under PAM.




