Glossary
Access review
Also called: user access review, entitlement review
An access review is a periodic check that the people who have access to something still need it. It is the control that catches accumulated permissions, and it depends entirely on being able to report who can reach what — which many systems cannot do usefully.
Access review explained
What it is looking for
Access that made sense once and does not now. Someone who moved teams and kept their old permissions. A share created for a project that ended two years ago. An external collaborator whose engagement finished. A role that accumulated permissions through a series of individually reasonable exceptions.
None of these are breaches. Together they are how an organisation loses the ability to state who can see what.
Why it depends on reporting
A review is only feasible if the system can answer "who has access to this folder" and "what can this person reach" without an administrator reconstructing it from configuration. If those two reports do not exist, the review becomes a sampling exercise and stops being a control.
A shared-access overview listing every active share and per-document override is the other half: shares accumulate silently and are the most common way a permission model degrades.
Frequency and ownership
Quarterly for sensitive material, annually for the rest, and reviewed by the person accountable for the content rather than by IT — IT knows who has access, and only the content owner knows whether they should. A review performed by the wrong person is a rubber stamp.
FAQ
Access review: common questions
Who should perform an access review?
The owner of the content, with IT supplying the report. IT can tell you who has access; only the owner can say whether that is still appropriate.
Is single sign-on a substitute for access reviews?
It solves leavers, which is the largest single problem, and it does not solve movers or accumulated shares. Both still need reviewing.
Related terms
- API keyAn API key authenticates a program rather than a person.
- Break-glass accessBreak-glass access is a deliberate, time-boxed grant of permissions a user does not normally hold, for genuine emergencies.
- Data residencyData residency is the commitment that data is stored and processed within a specified country or region.
- Encryption at restEncryption at rest protects stored data by encrypting it on disk, so that physical access to the storage medium does not yield readable content.
- Permission inheritancePermission inheritance means a document takes its access rights from the folder containing it, rather than being permissioned individually.
- Role-based access controlRole-based access control grants permissions to roles rather than to individuals, and assigns people to roles.
Last reviewed: August 28, 2026. Browse the full glossary.