Security playbook · AI Employee: Sig

User Access Reviews (UAR)

UAR completed on time for 100% users; auto-revoke reduces standing access

The problem

Quarterly access reviews are the compliance-driven ritual nobody enjoys. Managers get a spreadsheet of every employee's every entitlement and asked to tick keep/revoke. Most tick everything (safest for their team's velocity). Reviews complete, compliance passes, standing access grows. The ritual doesn't actually improve security posture.

At a glance
Trigger
Cron (quarterly)
Approvals
Manager attests per user; security reviews escalations
What it does
Writes to your systems
Systems
Okta · Salesforce · GitHub · AWS · GCP
How it feels in production

An hour-by-hour walkthrough.

Q3 review kicks off. Sig assembles reviewer packets: one per manager, listing their direct reports and the entitlements each has (SSO groups, SaaS licences, cloud IAM roles). For each entitlement, Sig annotates: when it was granted, when it was last used, and whether it's above the requester's team-baseline (flag). Manager gets a Slack DM: "Q3 access review. 12 reports, 47 entitlements total. Estimated 15 min. Start here." In review: each entitlement shows a smart default (keep for actively-used baseline entitlements; suggest revoke for unused > 90 days or above-baseline). Manager can accept the defaults in bulk or drill into specifics. Every decision one tap. 45 minutes later: manager submits. Sig writes: 12 entitlements auto-revoked (unused), 3 delegated for further review (skip-level), 32 kept, 0 escalated. Certification signed with digital signature. Aggregate: Q3 review closed on time, 8% of entitlements revoked (up from 2% in previous manual reviews), no false-positive productivity impact. SOC 2 evidence bundled: managers who signed, when, what they approved.
How it works

Step by step.

  1. 01

    Enumerate access per user per system

    Sig pulls entitlements from every system in scope (Okta, AWS IAM, GCP IAM, Salesforce, Confluence, GitHub, etc.). Deduplicates and normalises across sources. Filters to reviewable entitlements (excludes system-managed, break-glass).

    Okta · AWS IAM · GCP IAM · Salesforce · Confluence · GitHub
  2. 02

    Build reviewer packet by manager

    For each manager, assembles a packet: their direct reports, each report's entitlements, annotations (grant date, last used, above-baseline flag). Packet sized for 15-30 min review; large managers get progressive disclosure.

    Context Graph · Dashboard
  3. 03

    Track attestations

    Every decision written to review record with timestamp + reviewer identity. Progress bar per reviewer. Aggregate dashboard for security team shows completion, revocations, delegations.

    Dashboard · Slack
  4. 04

    Auto-revoke on 'revoke' decisions

    Revoke decisions execute via the underlying identity provider on submission. Write to audit; propagate to downstream tools via SSO group sync. Employee gets a notification with the revocation reason.

    Okta · GCP IAM · AWS IAM · Slack
  5. 05

    Escalate missed deadlines

    Managers who don't complete by Day 14 escalate to skip-level. Skip-level who misses Day 21 escalates to CISO. Deadline enforcement is non-negotiable — compliance requires it.

    Slack · CISO dashboard
Systems and wiring

What you connect to make this run.

Okta · Microsoft Entra ID · Google Workspace

read+write

Read all group memberships + assignments. Write revocations on decision. Full audit trail via source-system's own change log.

AWS IAM · GCP IAM · Azure AD

read+write

Read role assignments + policies. Revocations write via role-unassignment API.

Salesforce · Confluence · GitHub · Notion

read+write

Application-level access reviewed for admins + elevated roles. Revocations propagate via SSO group sync where possible.

Vanta · Drata

write

Review outcomes ship to your compliance platform as SOC 2 evidence. Auto-links to the relevant control.

What changes

Before and after, honestly.

Review completion time
Before
4-6 weeks (extended deadlines + chase-ups)
After
10-14 days on schedule
Manager time per review
Before
2-4 hours across manual spreadsheet review
After
15-45 minutes with smart defaults + bulk actions
% of entitlements revoked per review
Before
1-3% (managers rubber-stamp)
After
8-15% (smart defaults + unused-flag drives real revocations)
SOC 2 evidence collection effort
Before
Days of screenshots + spreadsheets pre-audit
After
Zero (auto-bundled with each review cycle)
Frequently asked

Answers about this playbook.

How does this interact with our IGA (Sailpoint, Saviynt)?

Coexists. IGA holds the entitlement catalogue and policy rules; Sig runs the actual review flow in Slack (approvals, nudges, revocations). Review outcomes sync back to IGA for compliance record.

What about system-managed accounts (service accounts, break-glass)?

Excluded from manager review by default; reviewed separately by security team on a different cadence. Sig maintains the exclusion list.

Can managers request access on someone's behalf during review?

Yes — 'add access' is a valid review outcome. Same approval chain as ad-hoc group management, but bundled into the review workflow.

How does it handle contractors and vendors?

Reviewed by the sponsor (usually the internal employee who owns the vendor relationship). Sponsor gets the packet; same review flow.

What if a review reveals a compliance gap?

Findings surface to security lead in real time. Common patterns (specific over-privileged groups, systematically-ignored decisions) become the input for policy updates.

See it run on your data.

Free plan, no credit card. Connect the systems this playbook needs and run it against a past event first.