Access and Entitlement Review in Identity and Access Management
In Identity and Access Management (IAM) systems, the access review process is the general term for the work carried out to audit access. IAM products typically provide an infrastructure specifically for running these access control exercises. The most common type of review carried out within this infrastructure is the user access review.
User Access Review
A user access review is the process of regularly reviewing the entitlements held by a company’s employees. During this process, managers examine the access held by the people who report to them and make the necessary adjustments.
For Example
Let’s say the user Mert KAYA holds 10 entitlements across 3 different applications. When the access review process is sent to his manager through the IDM application, the manager is expected to make a decision on each one. In the image below, the entitlements the manager marked in red are the ones considered risky or otherwise flagged for removal. The entitlements marked in green are the ones the user should keep and the manager does not want removed.

Access Review with an IDM Tool
Access reviews carried out using an IDM tool can be organized under several headings:
- User Access/Role Review — managers reviewing their users
- Entitlement Owner Access/Role Review — entitlement owners reviewing the users holding their entitlements
- Application Owner Access/Role Review — application owners reviewing the entitlements and roles granting access to their application
Advantages of an IDM Tool in Access Review Processes
In applications integrated with an IDM tool, access review processes can be carried out far more efficiently. For example, entitlements that a manager flags for removal during a user review can be automatically revoked once the certification campaign ends. These processes can also be reported on and tracked, which makes management and audit considerably more effective.