- 12 managers haven’t responded
- 23 managers approved everything without reviewing
- 5 managers asked “what is this?” and needed the entire process explained
- Zero meaningful security improvements resulted
The Access Review Fantasy
Here’s how access reviews are supposed to work:- Export who has access to what
- Send to managers for review
- Managers thoughtfully evaluate each person’s access
- Managers revoke inappropriate access
- Security posture improves
- Export who has access to what
- Send to managers for review
- Managers panic because they have 200 rows to review and don’t know what half the groups do
- Managers approve everything to avoid breaking something
- IT checks the “access review completed” box for compliance
- Nothing changes
Why Access Reviews Fail
1
Managers don't have the context
“Should Sarah still have access to
prod-deploy-eng?” Sarah’s manager has no idea. They don’t know what that group does, when Sarah got it, why she got it, whether her current role needs it, or what would break if they removed it. So they approve it. Better safe than sorry.2
The spreadsheet is overwhelming
A manager receives 200 rows to review. Each row has user name, group name (often cryptic like
okta-grp-eng-tools-v2), system name, and date granted. The manager has 2 weeks and 47 other priorities. They spend 10 minutes scanning it, approve everything, and move on.3
Reviews show what people have, not what they should have
Access reviews are backward-looking. They show current state. They don’t show what access this person should have based on their current role, what access they’re missing that they should have, or what access is baseline entitlement vs. exception. False negatives are invisible. If Sarah should have access but doesn’t, the review won’t catch it.
4
Reviews happen too infrequently
Quarterly reviews mean someone can operate with excessive privilege for 3 months before anyone notices. And that’s assuming the review catches it—it usually doesn’t.
5
There's no clear action when something's wrong
Manager finds inappropriate access. Now what? Do they remove it immediately (might break something critical)? Do they investigate why it was granted (don’t have time)? Do they consult with IT (creates a ticket that sits in the queue)? Do they approve it and make a mental note to “look into it later” (this is what actually happens)?
The Real Purpose of Access Reviews
The uncomfortable truth: access reviews exist for auditors, not for security. They’re a compliance checkbox. They create paper trails. They demonstrate “governance.” But they don’t meaningfully reduce risk. If access provisioning is wrong, quarterly reviews won’t fix it. They just document the wrong state four times a year.What Actually Works: Continuous Access Compliance
Companies with genuinely good access governance don’t rely on quarterly reviews. They use continuous compliance—where access is validated constantly, not four times a year. Here’s the model:1. Define Expected State (Policy)
Instead of asking “does Sarah have access to X?” ask “should Sarah have access to X based on her current role?” Define this as policy:2. Continuous Reconciliation
Compare actual state (what people have) to expected state (what policy says they should have) every day. Not quarterly. Daily.3. Exception Management
When someone needs access that’s not in their role’s policy, it should be: Explicit: “Sarah needs platform-engineering access for Q4 migration project” Temporary: “Expires 2025-01-31” Approved: “Approved by [email protected]” Tracked: “Automatically removed on expiration unless renewed” Exceptions are first-class citizens in the system, not shadow IT.4. Manager Review for Exceptions Only
Instead of reviewing 200 rows of “is this correct?” managers review 8 rows of “these are exceptions to policy. Should they continue?” That’s a conversation managers can actually have.The Benefits of Continuous Compliance
1
Drift is visible immediately
Someone manually grants access outside of policy? The system flags it within 24 hours. Investigation happens while context is fresh, not 90 days later.
2
Managers focus on exceptions, not baselines
Managers aren’t reviewing whether every Sales Engineer has the Sales Team group (that’s policy). They’re reviewing the 5% of access that’s unusual.
3
Audit evidence is continuous
Auditors don’t see “we reviewed access in Q1, Q2, Q3, Q4.” They see “policy defines expected access, system validates compliance daily, all drift is tracked and justified.” That’s stronger evidence than quarterly spreadsheets.
4
Access is always correct
When Sarah’s role changes from Sales Engineer to Product Manager, the system immediately knows what access she should lose (Sales Engineer baseline entitlements), what access she should gain (Product Manager baseline entitlements), and what exceptions persist (project-based access with defined expiration). Her access is correct within hours, not months.
5
Security posture actually improves
Continuous compliance catches privilege creep (accumulation across role changes), orphaned access (people who left but still have access), policy violations (manual grants outside approved patterns), and stale exceptions (temporary access that should have expired). It finds and fixes security issues rather than just documenting them.