A quarterly access review is the scheduled reconciliation of who can reach what against who should: active accounts compared to the current roster, and each person's permissions compared to their current role. It is the safety net under every other access control — the mechanism that catches what onboarding, offboarding, and role-change processes missed, before the gap ages into an incident.
Every access process has failures. The review is what bounds their lifespan to ninety days instead of forever.
Three reconciliations, in ascending order of effort:
Accounts versus roster. Every active account in every system that matters, matched against current employees and engaged contractors. The findings are departures whose access survived, contractors whose engagements ended, and accounts nobody can attribute at all. This is the highest-yield check and the easiest — it is a list comparison.
Access versus role. For the people who remain, does what they hold match what they do? The findings here are accretion: permissions carried across transfers, project access that outlived the project, coverage rights from a leave two years ago.
Privilege versus need. The short list of high-consequence holdings reviewed by name: payroll modification rights, banking detail access, administrative roles, bulk export capability, and the integrations and service accounts — the non-human population that every review skips and every attacker finds.
The cadence is a trade. Annual reviews leave failures standing for up to a year — long enough for a departed employee's live account to matter. Monthly reviews collapse into rubber-stamping because the volume exceeds anyone's attention. Quarterly keeps each cycle small enough to do honestly and frequent enough that the standing exposure stays short.
The scope can be tiered to match: the accounts-versus-roster check on everything each quarter, the role-appropriateness pass on high-consequence systems each quarter and everything else annually.
The known failure mode of access reviews is attestation theater: a manager receives a forty-row spreadsheet, has a meeting in ten minutes, and clicks approve-all. The review completes, the record shows diligence, and nothing was reviewed.
What produces genuine review:
Organizations running their first real reconciliation reliably surface the same set: accounts for people who left months or years ago; the shared login everyone forgot was shared; vendor access from an implementation completed long ago; a former payroll employee, now in operations, who can still open the register; and administrative rights held by twice as many people as anyone guessed.
The discomfort of that first list is the argument for the practice. Every item on it was invisible until someone looked, and each had been standing exposure the whole time.
Beyond risk reduction, the review produces the artifact that external audiences increasingly demand. Cyber insurance applications ask whether access is reviewed periodically. Client security questionnaires ask the same. Privacy frameworks expect demonstrable limitation of access to personal data. And after an incident, the documented review history is the difference between "we maintained reasonable controls" as a claim and as a record.
A one-page summary per cycle — date, scope, findings, removals — is all the artifact needs to be.
The review fails most often by never starting: it is nobody's job, so it is nobody's fault when it lapses. The fix is ownership and calendar — a named owner, a recurring date, a distribution of small batches to the managers who can actually judge them, and a standing rule that the found items get fixed.
For a mid-sized employer the honest cost is a few hours a quarter. Against the alternative — discovering at incident time that a departed administrator's account has been live for two years — it is the cheapest control in the catalog.
Employer's Guardian helps employers stand up review cycles, tie them to HR's joiner-mover-leaver data, and keep the records that prove them through outsourced HR services.
This article provides general educational information, not legal, tax, or insurance advice. Requirements vary by location, industry, and the data your organization handles.