← All posts · 2026-07-24
How to run a user access review for SOC 2
A user access review is the control auditors ask about most and companies improvise most. Here is a process that produces evidence an auditor will accept, without buying a compliance platform to get it.
Scope it honestly
Pick the systems that matter: identity provider, email, source control, production infrastructure, finance, and anything holding customer data. A review of six real systems beats a review of sixty apps nobody logs into.
Build the access list
For each system, export who has access and what role they hold. Most admin consoles export CSV. Normalize to four columns: person, system, role, manager. This snapshot is half your evidence, so date it.
Review with three verdicts
For every row, an owner or manager decides: keep, revoke, or flag for a change. The reviewer should be someone who knows the person's job, not just IT. Record who decided and when. Ambiguity is allowed during the review; it is not allowed in the record.
Close the loop on revocations
A review that finds stale access and does not remove it is worse than no review, because now there is a document proving you knew. Revoke within days, and note the completion date next to the decision.
Keep evidence an auditor can hold
The artifact that satisfies an audit is boring: the dated access list, the per-row decisions, the reviewer names, and proof the revocations happened. One printable record per campaign, filed where the next audit can find it.
Do it quarterly, small
An annual heroic review decays into a scramble. A quarterly review of the systems that matter takes an afternoon and turns the auditor conversation from negotiation into show-and-tell.
AccessKit runs your access reviews from a CSV import and produces printable evidence, no tenant access required. Start free or see the live demo.