User Access Review
A regular check of who can still log into your systems, and of the accounts nobody remembers creating.
Also known as access review user account audit permissions review
Definition
A user access review is a regular check of who can log into what. Someone sits down with a list of every account in the business and goes through it line by line. Most companies do it once every three months. It is dull work. It is also the fastest way to find out that your systems trust more people than you thought.
The list always holds surprises. The first is the person who left. Their email was closed on the last day, but the stock system, the delivery app and the online shop were never touched, so their login still works two years later. The second is the outside supplier. A marketing agency was given an account to load photos in 2021 and nobody ever asked for it back. The third is the shared manager login that four people use, with the password on a note under the keyboard.
Reviewing means more than reading names. For each account you decide three things. Is this person still with us. Do they still do the job that needed this access. And does the level still fit, or did it grow while they covered for someone. Anything you cannot answer gets switched off. Switching off is safe. If it turns out someone needed it, they ask for it back on Monday and you have learned something.
Two habits make the review painless. Linkysoft asks each manager to sign off their own team's list, because they know who left better than the office does. And write the date next to every decision, so next quarter you compare instead of starting again. A web application built for your trade should print that list itself, with the last login date beside each name. If yours cannot, the review turns into a week of spreadsheets, and it quietly stops happening.
The cost people do not expect is licences. Businesses pay every month for accounts belonging to people who left long ago. One review pays for itself. Linkysoft usually finds the biggest surprise in the third-party accounts, which is why our cybersecurity work starts with a full list of everyone who can log in. Ask for that list today and watch how long it takes somebody to produce it.
Questions about User Access Review
How often should we check who has access?
Who should do the review, the manager or the technical team?
What do we do with an account nobody can explain?
Should suppliers and agencies be on the list?
How long does the first review take?
Still not sure how this applies to your project?
Tell us what you are building and we will answer in plain language.