A quarterly access review you can finish in an hour

Practical guides · About 6 minutes

Access only ever accumulates. People get added and rarely removed, temporary permissions become permanent, and integrations you approved in 2023 still hold a token. Nothing forces a cleanup, so it doesn't happen — until an incident forces it at the worst possible moment. The fix is a small, boring, time-boxed review you can actually sustain.

Make it finishable

The reason access reviews don't happen is that people design them to be thorough, discover they take a full day, and never schedule the second one. A review you do four times a year at 80% coverage beats a perfect one you do once and abandon.

So: put an hour in the calendar, quarterly, and treat the hour as fixed. If you run out of time, note where you stopped and start there next quarter. Work down by tier, so the hour is always spent on the highest-consequence accounts first.

The one prerequisite

You need the inventory. Without a list of accounts, a review becomes a memory exercise and you'll miss exactly the forgotten accounts that most need looking at. If you don't have one yet, spend the first session building it — that is the first review.

The six checks

1. People who shouldn't still be there

Open the user list on each Tier 1 and Tier 2 service and read every name. You're looking for former staff, former contractors, an agency you stopped working with, and the personal address of someone who now has a company one.

Two things reliably survive an offboarding that looked complete: accounts on services nobody remembered were in use, and accounts under a personal email address that didn't match the pattern anyone searched for. Reading the list beats searching it.

2. Permissions that outgrew their purpose

For everyone still on the list, ask whether their role still matches what they do. The usual finding is a cluster of Admins who needed admin once, for one task, in a hurry.

Downgrading is low-risk and easily reversed — if you cut too deep, someone asks and you restore it in thirty seconds. Compare that to the cost of a compromised admin account, and the asymmetry is obvious.

3. Tokens, keys, and connected apps

The most-neglected check and often the most productive. Look for API keys and personal access tokens, OAuth grants to third-party applications, app-specific passwords, webhooks pointing at endpoints you no longer run, and SSH or deploy keys.

These persist independently of the account that created them. Disabling a user often leaves their tokens working. Revoke anything you can't positively identify — a token nobody can explain is either unused or unknown, and both are reasons to remove it. See the tokens guide for what to look for on each type of service.

4. Shared credentials

Pull up your shared vault collections and, for each item, ask three questions: is it still needed at all; is the group still correct; and has the vendor added real user management since you last checked?

That third one changes more often than you'd expect. Products add seats and roles as they mature, and nobody sends you a note when yours does. A shared login that was unavoidable two years ago may be avoidable now — check before renewal, when you have leverage.

5. Recovery paths

Quick but important, and Tier 1 only. On each account, look at the recovery email addresses and phone numbers on file. Remove anything belonging to someone who left, any number you no longer control, and any address at a provider you've stopped using.

A stale recovery contact is a live credential in someone else's hands. Phone numbers get reassigned; old work addresses get reissued.

6. Accounts you no longer need

The trial you never cancelled, the tool replaced by another tool, the client whose contract ended. Each one holds data, has credentials attached, and is watched by nobody.

Close them properly — export anything you're required to keep, then delete the account rather than just letting the subscription lapse. A cancelled subscription often leaves the account and its data intact and still reachable with the old password.

Working the hour

A rough allocation that fits:

MinutesWhat
0–20Tier 1: all six checks, thoroughly. Never skip this block.
20–40Tier 2: users, permissions, tokens.
40–50Shared credentials across all tiers.
50–60Write down what you changed and where you stopped.

Tier 3 gets whatever is left, which is usually nothing. That's the correct trade — a stale user on a reporting dashboard is a much smaller problem than a stale token on your cloud account.

The last ten minutes matter more than they look. A short note — what you removed, what you deliberately left, where the hour ran out — turns four disconnected hours a year into something cumulative. Next quarter starts where this one stopped instead of starting over.

What to skip

Reviews collapse under their own weight when they try to do too much. Explicitly out of scope:

Events that trigger a review outside the schedule

The quarterly cadence catches drift. Some things shouldn't wait for it:

Making the next one faster

Each review should be quicker than the last, and a few habits compound:

Record grant dates and reasons when you add access, so future-you doesn't have to reconstruct why someone has admin. Prefer time-boxed access wherever a platform offers it, so some of the cleanup happens without you. Keep the inventory current as you add services rather than rebuilding it each quarter. And note which services have real user management and which don't — that turns "check whether they support seats now" from a full sweep into a short list.

None of this is sophisticated. It's the discipline of looking, on a schedule, at a list you already have — and it's the difference between an offboarding you can prove was complete and one you're hoping was.

Related guides