IT Glossary
An access review checks that user access is still appropriate. Learn how access reviews work, review vs certification, and how Corma automates them.
July 3, 2026
An access review (also called a user access review) is a periodic check in which managers or resource owners verify that each user's access rights are still appropriate and necessary. It identifies excessive, outdated, or orphaned access so it can be removed. Access reviews are a core control for ISO 27001, SOC 2, and NIS2, and a practical way to enforce least privilege over time.
An access review and an access certification are related but distinct. The access review is the act of checking whether access is still appropriate. The access certification is the formal, recorded sign-off that proves the review happened.
Each quarter, app owners at a SaaS company confirm whether their team still needs access to finance, code, and customer tools. The review surfaces a marketer who kept admin access to the billing system after a project ended, and it is revoked. Run in spreadsheets, this drags for weeks and rarely covers every app. Automated and pulled from live access data, it becomes fast and complete.
Many frameworks expect at least quarterly reviews for sensitive systems, with more frequent reviews for high-privilege access.
The review is the act of checking access. The certification is the documented sign-off that records the decision as audit evidence.
Because access is spread across dozens of apps. Manual reviews miss tools and consume weeks, while automated reviews pull live data and cover everything.