How to Run a Practical Quarterly Access Review
Access reviews fail when they try to review everything, prove nothing, and finish never. A scoped, evidence-first quarterly cycle takes hours — not weeks — and stands up to auditors and incidents alike.
Almost every framework asks for periodic access reviews, and almost every small team dreads them. The dread usually comes from a bad first attempt: an unscoped export of every account in every system, a spreadsheet nobody finishes, and a vague memory of “we looked at it” when the auditor asks for proof.
A quarterly review that actually works is narrower, faster, and produces its own evidence.
What this means
An access review is a recurring control with four parts: scope (which systems and accounts), review (does each account still need what it has), decision (keep, reduce, or remove — recorded, with a name attached), and remediation (changes actually made, within a deadline). If any part is missing, you have an activity, not a control.
The most common misconception is that the review must cover everything. It must cover what you said it covers — so say something achievable. A defensible first scope for most organizations is: the identity platform (Google Workspace or Microsoft 365/Entra ID), administrative roles in every business-critical SaaS application, VPN or remote access, production infrastructure, and every third-party or contractor account, everywhere.
Why it matters
Stale access is quiet risk. The accounts that hurt organizations in incidents are disproportionately the ones nobody was thinking about: the contractor whose project ended in March, the former employee’s mailbox delegate, the “temporary” admin role from a migration two years ago, the vendor account with a password that predates MFA enforcement.
A quarterly cycle keeps this population small. It is also one of the highest-leverage pieces of compliance evidence you can produce: the same worksheet satisfies SOC 2 logical-access criteria, NIST SP 800-171 access-control requirements, and most customer questionnaires — and it makes incident response faster, because you start from a current picture of who can touch what.
Practitioner actions
A repeatable quarter looks like this:
- Freeze the scope list. Maintain the in-scope system list in one place. Adding a system mid-review is how reviews die; queue it for next quarter.
- Extract, don’t transcribe. Pull user and role exports directly from each system’s admin console or API on a recorded date. Screenshots of admin-role pages are acceptable evidence for small SaaS tools without exports.
- One row per account. System, account, human owner (or “service”), role, privilege level, last activity if available. The Toolkit’s access review worksheet is this structure, ready to fill.
- Route decisions to the right reviewer. System owners judge business need; managers judge whether their reports still need access. IT should facilitate, not unilaterally decide business necessity.
- Record every decision — keep, reduce, remove — with reviewer name and a one-line justification for anything privileged that stays.
- Remediate within a stated window (ten business days is a common, achievable commitment) and mark each row done with a ticket link or change note.
- File the artifact. Dated worksheet, exports, and a two-paragraph summary: scope, findings count, removals, exceptions. That file is your evidence.
Expect the first cycle to be the slow one — it carries years of accumulated cleanup. Cycles after that are typically a fraction of the effort, because you are reviewing a quarter’s drift, not a decade’s.
Business actions
- Sponsor the deadline. Reviews stall when reviewers treat them as optional; a leader stating “decisions due by the 15th” is often the entire fix.
- Accept the output of reduced access. If a removal breaks something, the answer is a documented re-grant — evidence the process works — not a quiet return to standing admin for everyone.
- Ask for the summary, not the spreadsheet: scope, removals, anything privileged that stayed and why. Five minutes a quarter keeps leadership genuinely informed of access risk.
- If a customer or auditor request is on the horizon, start the cadence now. Two completed historical cycles are worth more than any written policy.
The bottom line
Scope deliberately, extract rather than transcribe, record decisions with names, remediate on a clock, and file the artifact. Done this way, a quarterly access review is an afternoon of coordinated work that pays for itself in both risk and audit currency.
References
- CIS Critical Security Controls — Center for Internet Security
- NIST SP 800-171 Rev. 3 — Protecting Controlled Unclassified Information — NIST Computer Security Resource Center