Skip to main content

Access Reviews

Access Reviews help you maintain compliance by periodically reviewing user permissions and access to ensure they align with the principle of least privilege.

Enterprise Feature

Access Reviews are available exclusively on the Enterprise plan.

Why Access Reviews?

Over time, users accumulate permissions that may no longer be needed. Access reviews ensure:

  • Users only have access they need
  • Permissions are revoked when no longer required
  • Compliance requirements are met (SOX, ISO 27001, etc.)
  • Security posture is maintained

Review Process

  1. Review Created: Admin schedules an access review with scope and due date
  2. Notifications Sent: Assigned reviewers are notified
  3. Review Period: Reviewers evaluate each user's permissions
  4. Actions Taken: Permissions confirmed or revoked
  5. Completion: Review is closed and documented for compliance

Features

FeatureDescription
Manual ReviewsAd-hoc reviews triggered by admins
Scheduled ReviewsRecurring reviews (monthly, quarterly)
Automated RemindersNotifications to reviewers as due date approaches
Custom Review ScopesReview all users, specific teams, or specific roles
Compliance ReportingGenerate reports showing review completion and actions taken

Next: Learn about Session Management.