How to run a user access review.

A user access review is a scheduled check of who can get into your important systems and whether they still should. It takes a few hours and catches problems that sit unnoticed for years.

Systems guide · By Elevated Vibration · Updated October 2026

What it is for

Access builds up. People change roles and keep their old permissions. Contractors finish and their accounts stay active. A review finds those and removes them. It is also a control most SOC 2 audits expect to see done on a schedule, commonly every quarter.

Choose the systems

Start with the ones that hold customer data or control your infrastructure:

  • Identity provider
  • Cloud hosting
  • Code repository
  • Production databases
  • HR and finance systems
  • Password manager and other admin tools

Run the review

  • Export the current list of users and their permission levels from each system.
  • Compare it with the current employee list from your HR system.
  • Send each system owner or manager their list and ask them to confirm, for every person, that the access is still needed at that level.
  • Pay particular attention to administrator accounts, shared accounts and anyone outside the company.

Act on what you find

  • Remove accounts for people who have left.
  • Reduce permissions that are higher than the role needs.
  • Give shared accounts a named owner or replace them with individual logins.
  • Record each change and the date it was made.

Document it

Keep the exported lists, the reviewer's sign-off with a date, and the record of changes. That set is the evidence. A review that happened but was not documented does not count in an audit.

Make the next one easier

  • Put the review on the calendar for the same week each quarter.
  • Connect systems to single sign-on so access is managed in one place.
  • Tighten offboarding so there is less to find next time.

We run access reviews for you, chase the sign-offs and keep the evidence in order. See SOC 2 readiness and audit management.

Related articles

The SOC 2 Audit Period: What You Have to Prove

During the three-month audit period, someone has to keep the tests passing and collect proof that your controls are really being used.

Employee Onboarding and Offboarding Checklist

A repeatable checklist for bringing people in and out, including accounts, equipment and access.

How to Roll Out a Password Manager at a Small Company

A practical rollout plan: structure, settings, moving shared logins and getting everyone to actually use it.

Common questions

Straight answers.

How often should user access reviews be done?

On the schedule your policy sets. Quarterly is common for important systems.

Who should perform a user access review?

The owner of each system or the manager of each team confirms access. One person coordinates the review and keeps the records.

Is a user access review required for SOC 2?

SOC 2 does not prescribe specific procedures, but periodic access reviews are one of the controls auditors most commonly expect.

Want access reviews handled?

Tell us which systems you run. We'll tell you what it will take.

Book a free call