User Access Review
A user access review is a periodic audit confirming that every account and permission maps to a current person and a current need — and revoking the rest.
A user access review (also called an access recertification or entitlement review) is a periodic, documented check that every account and permission in a system still maps to a real, current person with a genuine business need. Reviewers — usually the managers or system owners who can actually judge the need — confirm each entitlement or flag it for removal. Frameworks including ISO 27001, SOC 2, PCI DSS and NIST SP 800-53 all expect some form of it, typically quarterly for sensitive systems and at least annually elsewhere.
How it becomes a security problem
Skipped or rubber-stamped reviews are how access quietly rots. Without recertification, privilege creep accumulates unchecked, orphaned accounts from departed staff and expired contractors stay live, and shared or service accounts drift with passwords no one has rotated. The review is often the only control that catches what automated deprovisioning missed — the SaaS tool outside single sign-on, the direct database grant, the admin console signed up with a personal email. The common failure mode is volume: a manager confronted with four hundred line items approves all of them in bulk, and the exercise produces an audit artifact instead of a security outcome.
How to defend against it
Design reviews people can actually perform. Keep scopes small and frequent rather than annual and enormous; show reviewers what each permission means and when it was last used, so "never used in 12 months" becomes an easy revoke; and make removal the default for anything unconfirmed by the deadline. Prioritize the systems where a wrong answer hurts most — production infrastructure, finance, customer data, and anything reachable by privileged accounts. Feed the results back into joiner-mover-leaver automation so the same gap does not reopen each quarter, and pair the cadence with the same-day leaver controls in our guide to departing-employee risk — the review is the safety net, not the door itself. Access data also sharpens the human-risk picture: reach and behavior together are what a human risk score is built to weigh.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo