A quarterly access review you can finish in an hour
Access only ever accumulates. People get added and rarely removed, temporary permissions become permanent, and integrations you approved in 2023 still hold a token. Nothing forces a cleanup, so it doesn't happen — until an incident forces it at the worst possible moment. The fix is a small, boring, time-boxed review you can actually sustain.
Make it finishable
The reason access reviews don't happen is that people design them to be thorough, discover they take a full day, and never schedule the second one. A review you do four times a year at 80% coverage beats a perfect one you do once and abandon.
So: put an hour in the calendar, quarterly, and treat the hour as fixed. If you run out of time, note where you stopped and start there next quarter. Work down by tier, so the hour is always spent on the highest-consequence accounts first.
You need the inventory. Without a list of accounts, a review becomes a memory exercise and you'll miss exactly the forgotten accounts that most need looking at. If you don't have one yet, spend the first session building it — that is the first review.
The six checks
1. People who shouldn't still be there
Open the user list on each Tier 1 and Tier 2 service and read every name. You're looking for former staff, former contractors, an agency you stopped working with, and the personal address of someone who now has a company one.
Two things reliably survive an offboarding that looked complete: accounts on services nobody remembered were in use, and accounts under a personal email address that didn't match the pattern anyone searched for. Reading the list beats searching it.
2. Permissions that outgrew their purpose
For everyone still on the list, ask whether their role still matches what they do. The usual finding is a cluster of Admins who needed admin once, for one task, in a hurry.
Downgrading is low-risk and easily reversed — if you cut too deep, someone asks and you restore it in thirty seconds. Compare that to the cost of a compromised admin account, and the asymmetry is obvious.
3. Tokens, keys, and connected apps
The most-neglected check and often the most productive. Look for API keys and personal access tokens, OAuth grants to third-party applications, app-specific passwords, webhooks pointing at endpoints you no longer run, and SSH or deploy keys.
These persist independently of the account that created them. Disabling a user often leaves their tokens working. Revoke anything you can't positively identify — a token nobody can explain is either unused or unknown, and both are reasons to remove it. See the tokens guide for what to look for on each type of service.
4. Shared credentials
Pull up your shared vault collections and, for each item, ask three questions: is it still needed at all; is the group still correct; and has the vendor added real user management since you last checked?
That third one changes more often than you'd expect. Products add seats and roles as they mature, and nobody sends you a note when yours does. A shared login that was unavoidable two years ago may be avoidable now — check before renewal, when you have leverage.
5. Recovery paths
Quick but important, and Tier 1 only. On each account, look at the recovery email addresses and phone numbers on file. Remove anything belonging to someone who left, any number you no longer control, and any address at a provider you've stopped using.
A stale recovery contact is a live credential in someone else's hands. Phone numbers get reassigned; old work addresses get reissued.
6. Accounts you no longer need
The trial you never cancelled, the tool replaced by another tool, the client whose contract ended. Each one holds data, has credentials attached, and is watched by nobody.
Close them properly — export anything you're required to keep, then delete the account rather than just letting the subscription lapse. A cancelled subscription often leaves the account and its data intact and still reachable with the old password.
Working the hour
A rough allocation that fits:
| Minutes | What |
|---|---|
| 0–20 | Tier 1: all six checks, thoroughly. Never skip this block. |
| 20–40 | Tier 2: users, permissions, tokens. |
| 40–50 | Shared credentials across all tiers. |
| 50–60 | Write down what you changed and where you stopped. |
Tier 3 gets whatever is left, which is usually nothing. That's the correct trade — a stale user on a reporting dashboard is a much smaller problem than a stale token on your cloud account.
The last ten minutes matter more than they look. A short note — what you removed, what you deliberately left, where the hour ran out — turns four disconnected hours a year into something cumulative. Next quarter starts where this one stopped instead of starting over.
What to skip
Reviews collapse under their own weight when they try to do too much. Explicitly out of scope:
- Reading audit logs. Valuable during an incident, not a good use of a routine hour. You're reviewing state, not history.
- Rotating passwords. Rotate on events, not on a calendar — see password hygiene. A review that turns into a rotation project won't get finished.
- Fixing everything you find. Remove what's clearly wrong, and write down what needs a conversation. The review's job is to surface, not to resolve.
- Perfect coverage. Tier 3 can wait a year. It genuinely can.
Events that trigger a review outside the schedule
The quarterly cadence catches drift. Some things shouldn't wait for it:
- Someone leaves — run the offboarding list in the access-sharing guide immediately.
- A contract or client relationship ends.
- A breach is disclosed at a service you use.
- A device is lost or stolen.
- You inherit a system from someone else — review before you rely on it, not after.
Making the next one faster
Each review should be quicker than the last, and a few habits compound:
Record grant dates and reasons when you add access, so future-you doesn't have to reconstruct why someone has admin. Prefer time-boxed access wherever a platform offers it, so some of the cleanup happens without you. Keep the inventory current as you add services rather than rebuilding it each quarter. And note which services have real user management and which don't — that turns "check whether they support seats now" from a full sweep into a short list.
None of this is sophisticated. It's the discipline of looking, on a schedule, at a list you already have — and it's the difference between an offboarding you can prove was complete and one you're hoping was.