Access reviews
A user-access review is a periodic check that the right people have the right access, and that leavers and stale accounts are gone. It is one of the controls auditors probe hardest, and Keel turns it from a spreadsheet chore into a repeatable, evidenced workflow.
Bring in your users
Section titled “Bring in your users”Start from a directory of accounts for the system you are reviewing. You can upload a CSV export of users, and on plans with directory sync you can connect a provider (such as Microsoft Entra ID or Google) so the roster comes in automatically and stays closer to current.
Review each account
Section titled “Review each account”For each account, confirm whether the access is still appropriate. Flag accounts that should be removed (a leaver, or access no longer needed) or changed (too much access for the role). Reviewing against least privilege, only what each person needs to do their job, is what keeps access from creeping over time.
Assign a reviewer and sign off
Section titled “Assign a reviewer and sign off”Give each review an accountable reviewer and a completion state. When the review is done, Keel records who reviewed it and when, the sign-off an auditor asks to see. Turn any flagged accounts into tasks so the actual removals and changes get done and are not just noted.
Keep a schedule
Section titled “Keep a schedule”Access reviews are periodic by nature. Keel tracks which systems have been reviewed, which are still outstanding, and which are overdue, so reviews happen on a cadence rather than only when an audit is looming.
Next steps
Section titled “Next steps”- Evidence: keep the completed review as proof the control operated.
- Tasks: make sure flagged removals and changes actually happen.
- Frameworks & crosswalks: one review can satisfy access requirements in several frameworks.