---
title: "Access Review — Identity Glossary | IDSync"
description: "An access review is a periodic check where managers or system owners confirm that each user's current access is still appropriate — typically required by…"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://idsync.com/"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Glossary",
          "item": "https://idsync.com/glossary"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Access Review",
          "item": "https://idsync.com/glossary/access-review"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "DefinedTerm",
      "@id": "https://idsync.com/glossary/access-review",
      "name": "Access Review",
      "alternateName": [
        "access certification",
        "user access review",
        "UAR"
      ],
      "description": "An access review is a periodic check where managers or system owners confirm that each user's current access is still appropriate — typically required by SOX, SOC 2, ISO 27001, and HIPAA.",
      "url": "https://idsync.com/glossary/access-review",
      "inDefinedTermSet": "https://idsync.com/glossary"
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "How often should reviews run?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Quarterly for high-risk apps (financial, PHI, production); annually for low-risk apps. SOX-relevant systems typically require quarterly."
          }
        },
        {
          "@type": "Question",
          "name": "How is this different from IGA?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Access reviews are a *capability* of IGA. IGA also covers provisioning, role mining, SoD, and policy enforcement."
          }
        }
      ]
    }
  ]
---

[![IDSync — identity software buyer platform](/assets/idsync-logo-BKS89EW4.png)](/)

[Directory](/directory)

[Compare](/compare)

[Resources](/resources)

[Browse tools](/directory)[Run Stack Finder](/stack-finder)

1.  [Home](/)
2.  [Glossary](/glossary)
3.  Access Review 

Identity Governance

# Access Review

An access review is a periodic check where managers or system owners confirm that each user's current access is still appropriate — typically required by SOX, SOC 2, ISO 27001, and HIPAA.

Last reviewed 3 months ago

Key points

-   Compliance-driven: SOX, SOC 2, ISO 27001, HIPAA, PCI
-   Run quarterly or semi-annually for in-scope systems
-   Increasingly informed by usage data, not just entitlement lists
-   Automated by IGA tools (SailPoint, Saviynt, Lumos, ConductorOne, Zilla)
-   Failed reviews trigger deprovisioning workflows

## What it is

An access review (also called access certification or UAR — user access review) is a recurring control where the right person — a manager, app owner, or data owner — looks at who has access to a system and explicitly approves or revokes each user.

## How it works

An IGA tool pulls entitlements from in-scope apps (Salesforce, NetSuite, AWS, GitHub, etc.), groups them by reviewer, and presents a worklist: _Alice Chen has access to Salesforce — Sales Cloud + Admin. Keep / Remove?_ Decisions feed back into provisioning systems to revoke unneeded access automatically.

Modern reviews include usage data — _Alice hasn't used Admin in 90 days_ — so reviewers can make informed decisions instead of rubber-stamping.

## When buyers care

-   Preparing for SOX, SOC 2 Type II, ISO 27001, HITRUST, or FedRAMP audits
-   After acquisitions, layoffs, or major reorgs
-   Whenever an audit calls out 'access review fatigue' or rubber-stamp findings

## Common misconceptions

-   **Access reviews are not the same as offboarding.** Offboarding removes everything; reviews refine what's still needed.
-   **Spreadsheet reviews don't pass modern audits.** Auditors increasingly expect tooling with evidence trails.

## FAQ

### How often should reviews run?

Quarterly for high-risk apps (financial, PHI, production); annually for low-risk apps. SOX-relevant systems typically require quarterly.

### How is this different from IGA?

Access reviews are a _capability_ of IGA. IGA also covers provisioning, role mining, SoD, and policy enforcement.

IDSync provides educational buyer guidance based on publicly available information, editorial review, and user-submitted data. Vendor information should be verified before purchase. [Who we are, our methodology & disclosure policy](/about).

### One identity concept, explained per issue

Get vendor-neutral identity explainers and market updates in your inbox.

Work email\* 

Name

Company

Role (optional)

Interests (optional)

Pick what you want more of.

IAMCIAMSSO/MFAIGA/PAMSCIM/provisioningAI agent identityVendor updatesSecurity incidents

Subscribe

Twice-monthly identity digest. Curated, vendor-neutral. Unsubscribe any time.

### Vendor categories

[iga](/directory/category/iga)

### Vendors to evaluate

[sailpoint](/directory/sailpoint)[saviynt](/directory/saviynt)[lumos](/directory/lumos)

### Not sure which tool you need?

Run the IAM Stack Finder for a vendor-neutral shortlist tailored to your stack.

[Run the Stack Finder](/stack-finder)

### Explore tools for this topic

Browse vetted vendors in the iga category.

[Explore tools](/directory/category/iga)

[![IDSync home](/assets/idsync-logo-BKS89EW4.png)](/)

The buyer-focused platform for identity, access, and authentication software.

#### Platform

-   [Home](/)
-   [IAM Stack Finder](/stack-finder)
-   [Directory](/directory)
-   [Resources](/resources)
-   [State of AI Agent Identity 2026](/reports/state-of-ai-agent-identity-2026)
-   [Buyer Guides](/guides)
-   [Glossary](/glossary)
-   [Newsletter](/newsletter)
-   [Newsletter Archive](/newsletter/archive)

#### Best of guides

-   [All comparisons](/compare)
-   [All vendor alternatives](/alternatives)
-   [Best SSO tools](/compare/best-sso-tools)
-   [Best MFA tools](/compare/best-mfa-tools)
-   [Best PAM tools](/compare/best-pam-tools)
-   [Best IGA tools](/compare/best-iga-tools)
-   [Best CIAM tools](/compare/best-ciam-tools)
-   [Best passwordless auth](/compare/best-passwordless-authentication-tools)
-   [Best identity security](/compare/best-identity-security-tools)
-   [Best machine identity](/compare/best-machine-identity-tools)
-   [Best SaaS access governance](/compare/best-saas-access-governance-tools)
-   [Best developer auth](/compare/best-developer-authentication-tools)
-   [Best for startups](/compare/best-iam-tools-for-startups)
-   [Best for enterprises](/compare/best-iam-tools-for-enterprises)
-   [Best SCIM tools](/compare/best-scim-provisioning-tools)
-   [Best for AI agents](/compare/best-ai-agent-identity-tools)
-   [Best NHI tools](/compare/best-nhi-management-tools)
-   [Okta pricing explained](/guides/okta-pricing)
-   [Auth0 pricing explained](/guides/auth0-pricing)
-   [Okta alternatives](/alternatives/okta)
-   [Auth0 alternatives](/alternatives/auth0)

#### For Vendors

-   [Sponsor](/sponsor)
-   [Badges](/badges)
-   [Submit Product](/submit-product)
-   [Claim Profile](/claim-profile)
-   [Partner](/partner)

#### Company

-   [About & Methodology](/about)
-   [Contact](/contact)
-   [Privacy](/privacy)

Vendor names, logos, and trademarks are the property of their respective owners. IDSync is an independent buyer resource and does not imply endorsement unless explicitly stated. Logos are displayed for identification purposes only.

IDSync (idsync.com) is operated by TetraCore, Bowling Green, Ohio. It is not affiliated with the IDSync® Active Directory synchronizer by Identity Syncronizer — [learn more](/about#idsync-disambiguation).

© 2026 IDSync. All rights reserved.

Editorial independence. Sponsored placements are clearly disclosed.