User Access Review

A regular check of who can still log into your systems, and of the accounts nobody remembers creating.

Also known as access review user account audit permissions review

Definition

A user access review is a regular check of who can log into what. Someone sits down with a list of every account in the business and goes through it line by line. Most companies do it once every three months. It is dull work. It is also the fastest way to find out that your systems trust more people than you thought.

The list always holds surprises. The first is the person who left. Their email was closed on the last day, but the stock system, the delivery app and the online shop were never touched, so their login still works two years later. The second is the outside supplier. A marketing agency was given an account to load photos in 2021 and nobody ever asked for it back. The third is the shared manager login that four people use, with the password on a note under the keyboard.

Reviewing means more than reading names. For each account you decide three things. Is this person still with us. Do they still do the job that needed this access. And does the level still fit, or did it grow while they covered for someone. Anything you cannot answer gets switched off. Switching off is safe. If it turns out someone needed it, they ask for it back on Monday and you have learned something.

Two habits make the review painless. Linkysoft asks each manager to sign off their own team's list, because they know who left better than the office does. And write the date next to every decision, so next quarter you compare instead of starting again. A web application built for your trade should print that list itself, with the last login date beside each name. If yours cannot, the review turns into a week of spreadsheets, and it quietly stops happening.

The cost people do not expect is licences. Businesses pay every month for accounts belonging to people who left long ago. One review pays for itself. Linkysoft usually finds the biggest surprise in the third-party accounts, which is why our cybersecurity work starts with a full list of everyone who can log in. Ask for that list today and watch how long it takes somebody to produce it.

Questions about User Access Review

How often should we check who has access?
Every three months for anything holding money or customer records. Once a year is enough for a small quiet system. Always do one straight away when somebody leaves.
Who should do the review, the manager or the technical team?
Both, with different jobs. The technical team produces the list of accounts. The manager of each team decides who still needs what, because only they know how the work changed.
What do we do with an account nobody can explain?
Switch it off, do not delete it. Keep a note of the date and who decided. If it turns out to be needed, turning it back on takes a minute, and now you know who owns it.
Should suppliers and agencies be on the list?
Yes, and they are the most forgotten. Outside accounts are handed out for one job and stay open for years. Check them first, because nobody inside the business will miss them.
How long does the first review take?
In a business of twenty people, an afternoon if the software prints the account list, and most of a week if it does not. The second review always takes a fraction of the first.

Still not sure how this applies to your project?

Tell us what you are building and we will answer in plain language.