How to Start an Access Review

An access review checks who can use your business systems and whether each person still needs that access. A clear review can help you spot former employees’ accounts, excessive permissions, and accounts with no clear owner. Start with a defined scope and a reliable account inventory, then verify access with the people who understand each system. Record every decision and change so you can follow up, answer questions, and repeat the process consistently.

Set the Scope and Owners

List the systems that hold business data or support important work. Include email, file storage, payroll, customer management, finance, collaboration, remote access, and any industry-specific tools. Add cloud services, local applications, and systems managed by outside providers. If the full list feels large, begin with systems that contain sensitive information or control essential business operations.

Assign an owner to each system before reviewing its users. The owner should know how the tool is used and who approves access. Identify a coordinator to track progress, collect decisions, and follow up on unresolved items. Set a review period and a completion date, and agree on how reviewers will report concerns or request access changes.

Build an Account Inventory

For each system, export or collect a current user list from its administrative settings. Record the account name, person or service it represents, department or role, account status, assigned groups, permission level, and last sign-in when available. Note the data source and the date you collected it. A spreadsheet can work for a small review if access to the file is limited.

Compare each account against current employee and contractor records. Look for former staff, duplicate accounts, unrecognized names, shared logins, inactive accounts, and accounts tied to a vendor. Include service accounts used by software or integrations; identify their purpose and internal owner. Do not assume an account is unnecessary just because it has not been used recently—confirm its role before changing it.

Check Whether Access Fits

Ask each system owner or manager to confirm whether every person still needs access for their current responsibilities. Compare permissions with the work the person performs, not simply their job title. Check whether users have administrator rights, access to sensitive records, or permission to approve payments or make other high-impact changes. Investigate access that appears broader than the role requires.

Review group memberships and inherited permissions as well as direct assignments. A user may receive access through a department group, nested group, or shared workspace. Confirm that external users and vendors have a business purpose, a sponsor, and an expected end date where appropriate. When reviewers cannot verify a permission, record it as unresolved and assign someone to investigate rather than treating silence as approval.

Record and Verify Changes

Keep a decision log with the account, system, current access, review decision, reason, approver, action owner, and completion date. Use clear outcomes such as retain, reduce, remove, or investigate. For each requested change, note who will carry it out and when. Avoid recording passwords, authentication codes, or other secrets in the log.

After changes are made, check the system to confirm the access now matches the approved decision. Record evidence such as an updated user list or administrative audit entry, following your organization’s data-handling rules. Escalate blocked or overdue changes to the system owner. Store the inventory and decision log in a restricted location, and use the completed review to schedule the next one.

A useful access review is a repeatable process: define the systems, confirm each account and permission with an owner, then document and verify every change. Start with a manageable group of high-priority tools and improve your inventory as you go. Memphis Identity Group can help your business plan a practical review and organize its access records.