GRC Oversight
Checklist

Quarterly access-review checklist

A user access review only counts as evidence if it's real access, a real decision, and a real revocation. Work through this before you close the campaign.

Before you launch a campaign

  • Decide the scope: which systems, teams, or sensitivity tiers this campaign covers.
  • Confirm each in-scope system's access list is current, not a stale export from last quarter.
  • Identify the right reviewer for each scope: usually a manager or system owner, not a single central admin.

Give reviewers real access, not a guess

  • Pull together who can actually reach what, aggregated from your connected systems.
  • Scope each reviewer to only the access that's theirs to judge.
  • Surface context that helps a decision: role, last login, why the access was granted.

Run the review

  • Give reviewers a clear approve-or-revoke action per user, not an open-ended spreadsheet.
  • Send reminders on a cadence so campaigns don't stall halfway through.
  • Track completion status so you can see who's done and who still needs a nudge.

Follow revocations through to done

  • A 'revoke' decision isn't evidence until the access is actually removed.
  • Track each revoke decision to completion, not just to the click that recorded the decision.
  • Re-check that revoked access doesn't quietly come back (e.g. via a group membership) before closing the campaign.

Capture the evidence

  • Record every decision with the reviewer, a timestamp, and any notes.
  • Export the full campaign (decisions, completion status, and revocation follow-through) mapped to the access-control requirement it satisfies.
  • Keep the signed history; most frameworks want to see access reviews over time, not just the most recent one.

This is the workflow our access-reviews product runs on: scheduled campaigns, real access, and revocations tracked to completion.