Guides
How-to

How to run a user access review (step by step)

A practical, step-by-step guide to running a user access review for SOC 2 or ISO 27001, how to scope it, pull current access, decide what to keep, and capture the evidence auditors ask for.

How-to8 min readUpdated June 11, 2026
FAQ
How often should you run a user access review?
Most SOC 2 and ISO 27001 programs expect at least quarterly reviews for sensitive systems, and at minimum annually for everything else. The cadence matters less than doing it consistently and keeping the evidence.
Who should review each user’s access?
The person accountable for the system, ideally a named tool owner who knows what access that tool should grant, with an admin as a backstop. Reviews done by someone without context tend to rubber-stamp.
What evidence does a user access review need to produce?
A record, for the period under review, of what access existed, who reviewed it, what was kept or removed, and when, timestamped and exportable. An append-only log produces this as a byproduct rather than a manual artifact.
Keep reading

Put your access on the record.

Free for up to 10 people and 20 tools. No credit card.

Start free