What it is for
Access builds up. People change roles and keep their old permissions. Contractors finish and their accounts stay active. A review finds those and removes them. It is also a control most SOC 2 audits expect to see done on a schedule, commonly every quarter.
Choose the systems
Start with the ones that hold customer data or control your infrastructure:
- Identity provider
- Cloud hosting
- Code repository
- Production databases
- HR and finance systems
- Password manager and other admin tools
Run the review
- Export the current list of users and their permission levels from each system.
- Compare it with the current employee list from your HR system.
- Send each system owner or manager their list and ask them to confirm, for every person, that the access is still needed at that level.
- Pay particular attention to administrator accounts, shared accounts and anyone outside the company.
Act on what you find
- Remove accounts for people who have left.
- Reduce permissions that are higher than the role needs.
- Give shared accounts a named owner or replace them with individual logins.
- Record each change and the date it was made.
Document it
Keep the exported lists, the reviewer's sign-off with a date, and the record of changes. That set is the evidence. A review that happened but was not documented does not count in an audit.
Make the next one easier
- Put the review on the calendar for the same week each quarter.
- Connect systems to single sign-on so access is managed in one place.
- Tighten offboarding so there is less to find next time.
We run access reviews for you, chase the sign-offs and keep the evidence in order. See SOC 2 readiness and audit management.
