High School AdvancedA13.8Identity, Zero Trust, and Access Control
Lesson A13.8
Access Reviews and Governance
Access review is where identity architecture becomes an ongoing governance process. The question is not whether access was valid when it was first granted; the question is whether it is still appropriate now.
This lesson uses fictional identities, entitlements, owners, review evidence, and governance decisions only. It does not require changing access in any real system.
High School Advanced • A13: Identity, Zero Trust, and Access Control • Lesson 8 of 10
80% complete
Readiness Check
A13.8 Entry Readiness
0/4 ready
Professional Hook
Good Access Can Become Bad Access When Responsibilities Change
A migration administrator may have needed production privilege three months ago. A partner may have needed a support console last month. A reporting analyst may still need dashboards but no longer need sensitive exports. Access review catches the gap between the access an identity currently holds and the access its current responsibility actually requires.
Access governance is lifecycle management for authorization.
Learning Objectives
Five Capabilities for This Lesson
1
Explain access review as a governance decision about whether a current identity-to-resource relationship should continue, change, expire, or be removed.
2
Evaluate access using business purpose, privilege, resource sensitivity, ownership, lifecycle, activity evidence, sponsorship, exceptions, and evidence freshness.
3
Distinguish Confirm, Reduce, Remove, Reassign, Expire, Review, and Accepted Risk as governance outcomes rather than treating every review as a simple yes/no certification.
4
Connect access review to workforce lifecycle, external sponsorship, privileged eligibility, workload identity, conditional access, federation, monitoring, and residual-risk decisions.
5
Build an Access Review Decision Register that becomes the eighth artifact in the A13 Enterprise Identity and Zero-Trust Review.
Review Dimensions
Eight Questions Behind a Strong Access Review
Current business or technical purpose
Why does this identity still need this resource or entitlement today?
Evidence
Current job responsibility, application dependency, project need, service ownership, partner support purpose, or approved operating function.
Warning
Historical usefulness is not enough when no current purpose exists.
Identity lifecycle
Has the user's role, team, employer, project, sponsor, workload, or service changed?
REV-03 shows that a migration project is closed, yet privileged eligibility for the former project administrator remains assigned.
Defensive recommendation: Remove the obsolete privileged eligibility and record closure evidence. A new future project should require a new approved access decision.
Use vs. Need
Activity Evidence Helps, but It Does Not Decide the Review by Itself
Recent use can support a legitimate need
A counselor regularly using role-appropriate application functions is useful evidence when current job responsibility and resource ownership also support the access.
Recent use can also expose overbroad access
A user may actively use a capability that is convenient but no longer required. Access review asks whether use is authorized by current purpose, not merely whether use occurs.
Low use also needs context.
Emergency recovery access may be rarely used and still be legitimate. Long-unused ordinary or privileged access, however, may indicate stale need. Governance uses purpose and lifecycle to interpret activity correctly.
A reporting analyst still needs the dashboard role, but the resource owner confirms that a separate sensitive-export entitlement is no longer required.
Scenario Decision Lab
Scenario Decision Lab 2 — Active but Unowned Legacy Access
A legacy reporting account still performs occasional production work. The current owner is Unknown, evidence is partial, and no valid current exception exists.
Safe Fictional Lab
Build an Access Review Decision Register
Use fictional identities, entitlements, resources, owners, lifecycle records, and synthetic activity evidence only. Do not modify any real access.
1
Create at least fifteen fictional access-review records.
2
Give every record a stable REV ID.
3
Record principal and principal type.
4
Record resource/application.
5
Record entitlement or privileged eligibility.
6
State current business or technical purpose.
7
Record privilege level.
8
Record lifecycle state.
9
Record identity owner, manager, sponsor, or service owner.
10
Record resource/entitlement owner.
11
Record recent activity evidence where appropriate.
12
Record evidence freshness.
13
Record exception or risk-acceptance status.
14
Choose Confirm, Reduce, Remove, Reassign, Expire, Review, or Accepted Risk.
15
Record the reason for the decision.
16
Record remediation or next action.
17
Record closure owner.
18
Record review/change trigger.
19
Include at least three workforce examples.
20
Include at least three privileged examples.
21
Include at least two external/partner examples.
22
Include at least two workload identities.
23
Include at least two temporary/project examples.
24
Include at least one unowned legacy entitlement and keep it Blocked.
25
Include at least one Accepted Risk record with owner, expiration, and target state.
Lab boundary
This is a fictional governance exercise. Do not inspect private access lists, remove real users, change group membership, alter roles, or modify any live identity or authorization system.
Analyze the Evidence
Evidence Analysis: Legacy Reporting Access
The legacy account still performs intermittent production activity.
The current owner is Unknown.
The current business need is uncertain.
Evidence is Partial.
No valid current exception exists.
What is the strongest governance state for REV-06?
Advanced Challenge
Run a Fictional Enterprise Access Review Board
A fictional organization has workforce roles, partner guests, privileged eligibility, workloads, temporary project access, emergency identities, and several legacy exceptions. Design a review board that can make consistent decisions without rubber-stamping everything.
1
Identity lifecycle evidence
2
Business purpose evidence
3
Resource sensitivity
4
Privilege level
5
Manager/sponsor input
6
Resource-owner input
7
Workload/service ownership
8
Activity evidence
9
Source health
10
Exception state
11
Risk owner
12
Confirm/Reduce/Remove logic
13
Reassignment logic
14
Expiration logic
15
Remediation ownership
16
Closure evidence
A mature review board should preserve legitimate access, reduce unnecessary scope, remove stale relationships, escalate uncertainty, and document who owns each follow-up action.
Defender Habits
A13.8 Defender Checklist
Skill Check
Seven Questions
Check Your Understanding
A13.8 Mini Quiz: Access Reviews and Governance
Choose your answers first. Explanations appear only after submission.
1. What is the main purpose of an access review?
2. A reporting analyst still needs dashboard access but no longer needs sensitive export capability. What is the strongest outcome?
3. Why should recent activity not automatically justify access?
4. A project ended but privileged eligibility remains assigned. What is the strongest review decision?
5. What should happen when an external partner's review date approaches?
6. What is strongest for an unowned legacy entitlement with partial evidence?
7. What makes a risk acceptance stronger?
Portfolio Prompt
Portfolio Build — Access Review Decision Register
Create the eighth artifact for your A13 Enterprise Identity and Zero-Trust Review: a fictional Access Review Decision Register with at least fifteen records. Include REV ID, principal, principal type, resource, entitlement, purpose, privilege, lifecycle, identity owner/manager/sponsor/service owner, resource owner, activity evidence, evidence freshness, exception/risk state, decision, rationale, remediation, closure owner, status, and next review/change trigger.
Use Confirm, Reduce, Remove, Reassign, Expire, Review, and Accepted Risk outcomes.
Include workforce, privileged, external, workload, and temporary access.
Treat activity as supporting evidence rather than automatic justification.
Keep Unknown ownership and stale evidence visible.
Include at least one explicit Accepted Risk with expiration and target state.
Use fictional provider-neutral records only.
Confidence / Readiness Reflection
Are You Ready for A13.9?
A13.9 moves into Balancing Security and Usability. Before continuing, make sure you can explain how an access review can preserve necessary work while reducing unnecessary friction and privilege.
1
I can explain access review as a lifecycle governance decision.
2
I can distinguish Confirm, Reduce, Remove, Expire, and Review outcomes.
3
I can explain why activity does not automatically justify access.
4
I can explain how privileged, external, and workload access need different evidence.
5
I can explain how exceptions and residual risk should remain visible.
Portfolio Build Guide
How to Make the Access Review Register Look Professional
Show the real entitlement
Do not stop at job title. Record the actual resource, role, privilege, or workload permission under review.
Show purpose and lifecycle
Make the current reason for access and the event that should change or end it visible.
Show multiple owners
Manager, sponsor, service owner, privileged-role owner, and resource owner may have different responsibilities.
Show evidence quality
Current, Partial, Stale, Missing, and Unknown evidence should affect review confidence.
Show the decision clearly
Use Confirm, Reduce, Remove, Reassign, Expire, Review, or Accepted Risk rather than vague notes.
Show remediation
Every reduction, removal, reassignment, or exception should have an owner and closure state.
Keep legacy uncertainty visible
Do not certify an account simply because removing it might be inconvenient.
Connect forward
A13.9 will evaluate how strong controls can remain usable, understandable, and proportionate.
Key Takeaways
What You Should Remember
1.Access review asks whether a current identity-to-resource relationship should still exist now.
3.Review outcomes can Confirm, Reduce, Remove, Reassign, Expire, or move access to Review/Unknown.
4.Activity is useful evidence but does not prove that access is justified.
5.Unused access can be stale, but rare emergency access may still be legitimate.
6.Privileged eligibility should be removed when the responsibility that justified it ends.
7.External identities require current sponsorship and lifecycle review.
8.Workload access should be reviewed when services, dependencies, or ownership change.
9.Risk acceptance should be explicit, bounded, and linked to residual risk and a target state.
10.The Access Review Decision Register will support A13.9 Balancing Security and Usability.
Lesson Safety Boundary
Access-review learning does not require changing real accounts
Do not remove real users, alter permissions, change roles, inspect private identity exports, or modify live access-control systems. All identities, entitlements, review evidence, and governance decisions in this lesson are fictional and defensive.
Lesson Complete
A13.8 Access Reviews and Governance Complete
You now have an access-governance model built around current purpose, lifecycle, privilege, ownership, activity evidence, sponsorship, exceptions, residual risk, remediation, and closure. Next, A13.9 focuses on Balancing Security and Usability.