User Access Reviews (UAR)
UAR completed on time for 100% users; auto-revoke reduces standing access
Quarterly access reviews are the compliance-driven ritual nobody enjoys. Managers get a spreadsheet of every employee's every entitlement and asked to tick keep/revoke. Most tick everything (safest for their team's velocity). Reviews complete, compliance passes, standing access grows. The ritual doesn't actually improve security posture.
An hour-by-hour walkthrough.
Step by step.
- 01
Enumerate access per user per system
Sig pulls entitlements from every system in scope (Okta, AWS IAM, GCP IAM, Salesforce, Confluence, GitHub, etc.). Deduplicates and normalises across sources. Filters to reviewable entitlements (excludes system-managed, break-glass).
Okta · AWS IAM · GCP IAM · Salesforce · Confluence · GitHub - 02
Build reviewer packet by manager
For each manager, assembles a packet: their direct reports, each report's entitlements, annotations (grant date, last used, above-baseline flag). Packet sized for 15-30 min review; large managers get progressive disclosure.
Context Graph · Dashboard - 03
Track attestations
Every decision written to review record with timestamp + reviewer identity. Progress bar per reviewer. Aggregate dashboard for security team shows completion, revocations, delegations.
Dashboard · Slack - 04
Auto-revoke on 'revoke' decisions
Revoke decisions execute via the underlying identity provider on submission. Write to audit; propagate to downstream tools via SSO group sync. Employee gets a notification with the revocation reason.
Okta · GCP IAM · AWS IAM · Slack - 05
Escalate missed deadlines
Managers who don't complete by Day 14 escalate to skip-level. Skip-level who misses Day 21 escalates to CISO. Deadline enforcement is non-negotiable — compliance requires it.
Slack · CISO dashboard
What you connect to make this run.
Okta · Microsoft Entra ID · Google Workspace
read+writeRead all group memberships + assignments. Write revocations on decision. Full audit trail via source-system's own change log.
AWS IAM · GCP IAM · Azure AD
read+writeRead role assignments + policies. Revocations write via role-unassignment API.
Salesforce · Confluence · GitHub · Notion
read+writeApplication-level access reviewed for admins + elevated roles. Revocations propagate via SSO group sync where possible.
Vanta · Drata
writeReview outcomes ship to your compliance platform as SOC 2 evidence. Auto-links to the relevant control.
Before and after, honestly.
Playbooks that pair with this one.
Just-In-Time (JIT) Access
The pattern that shrinks standing access before quarterly review even runs.
Cloud IAM Reviews
Cloud-IAM-specific variant with deeper role analysis.
GitHub Outside-Collaborator Review
GitHub-specific pattern for outside-collaborator drift.
Employee Offboarding
Terminated employees appear in review with 'terminated' flag; auto-revoke.
Answers about this playbook.
How does this interact with our IGA (Sailpoint, Saviynt)?
Coexists. IGA holds the entitlement catalogue and policy rules; Sig runs the actual review flow in Slack (approvals, nudges, revocations). Review outcomes sync back to IGA for compliance record.
What about system-managed accounts (service accounts, break-glass)?
Excluded from manager review by default; reviewed separately by security team on a different cadence. Sig maintains the exclusion list.
Can managers request access on someone's behalf during review?
Yes — 'add access' is a valid review outcome. Same approval chain as ad-hoc group management, but bundled into the review workflow.
How does it handle contractors and vendors?
Reviewed by the sponsor (usually the internal employee who owns the vendor relationship). Sponsor gets the packet; same review flow.
What if a review reveals a compliance gap?
Findings surface to security lead in real time. Common patterns (specific over-privileged groups, systematically-ignored decisions) become the input for policy updates.
See it run on your data.
Free plan, no credit card. Connect the systems this playbook needs and run it against a past event first.