Access Rights Review
An access rights review is a periodic check of who has access to an organization's systems and data, confirming that each person's permissions are still appropriate for their role. It helps ensure that only authorized individuals can reach key systems and that access no longer needed is removed. Organizations typically use it to support governance, risk management, and compliance efforts.
An access rights review (commonly called a user access review, or UAR) is a formal, periodic process in which user permissions across systems, applications, and data are evaluated to confirm they are appropriate, necessary, and aligned with each user's current role and the principle of least privilege. In practice, reviewers validate group membership and application access, identify and remediate excessive, stale, or orphaned entitlements, and document the review as evidence. In compliance engagements, such reviews are frequently relied upon to demonstrate logical access controls, for example, supporting the SOC 2 Security (Common Criteria) category or ISO/IEC 27001 access control objectives selected via the Statement of Applicability, though the specific frequency, scope, and evidentiary expectations vary by auditor, certification body, and defined scope.
Why it matters
Access rights tend to accumulate over time. As people change roles, join new projects, or leave the organization, the permissions they were granted often persist longer than the business need that justified them. Without a periodic check, this leads to excessive, stale, or orphaned entitlements, access that no longer maps to any legitimate role. An access rights review is the control that surfaces and corrects these drift conditions, helping ensure that only authorized individuals can reach an organization's key systems and data.
Beyond day-to-day hygiene, access rights reviews are a common focus of compliance engagements. In a SOC 2 examination, they frequently serve as evidence supporting the Security (Common Criteria) category's logical access controls, while under ISO/IEC 27001 they can support access control objectives selected through the Statement of Applicability. Because these are attestation and certification frameworks respectively, reviewers typically expect not just that access is appropriate but that the review itself is documented and repeatable. The specific frequency, scope, and evidentiary expectations vary by auditor, certification body, and defined scope.
It is worth noting the limits of the control. An access rights review confirms that permissions align with roles at the point the review is performed; it does not by itself prevent misuse of legitimately held access, nor does it guarantee freedom from breaches. Its value lies in reducing the standing attack surface and demonstrating governance, and it is most effective when combined with least-privilege provisioning and timely deprovisioning rather than treated as a standalone safeguard.
Who it's relevant to
Inside UAR
Common questions
Answers to the questions practitioners most commonly ask about UAR.