High School AdvancedA13.8Identity, Zero Trust, and Access Control

Lesson A13.8

Access Reviews and Governance

Access review is where identity architecture becomes an ongoing governance process. The question is not whether access was valid when it was first granted; the question is whether it is still appropriate now.

This lesson uses fictional identities, entitlements, owners, review evidence, and governance decisions only. It does not require changing access in any real system.

Lesson Progress

Access Reviews and Governance

High School AdvancedA13: Identity, Zero Trust, and Access Control • Lesson 8 of 10

80% complete

Readiness Check

A13.8 Entry Readiness

0/4 ready

Professional Hook

Good Access Can Become Bad Access When Responsibilities Change

A migration administrator may have needed production privilege three months ago. A partner may have needed a support console last month. A reporting analyst may still need dashboards but no longer need sensitive exports. Access review catches the gap between the access an identity currently holds and the access its current responsibility actually requires.

Access governance is lifecycle management for authorization.

Learning Objectives

Five Capabilities for This Lesson

1

Explain access review as a governance decision about whether a current identity-to-resource relationship should continue, change, expire, or be removed.

2

Evaluate access using business purpose, privilege, resource sensitivity, ownership, lifecycle, activity evidence, sponsorship, exceptions, and evidence freshness.

3

Distinguish Confirm, Reduce, Remove, Reassign, Expire, Review, and Accepted Risk as governance outcomes rather than treating every review as a simple yes/no certification.

4

Connect access review to workforce lifecycle, external sponsorship, privileged eligibility, workload identity, conditional access, federation, monitoring, and residual-risk decisions.

5

Build an Access Review Decision Register that becomes the eighth artifact in the A13 Enterprise Identity and Zero-Trust Review.

Review Dimensions

Eight Questions Behind a Strong Access Review

Current business or technical purpose

Why does this identity still need this resource or entitlement today?

Evidence

Current job responsibility, application dependency, project need, service ownership, partner support purpose, or approved operating function.

Warning

Historical usefulness is not enough when no current purpose exists.

Identity lifecycle

Has the user's role, team, employer, project, sponsor, workload, or service changed?

Evidence

Joiner/mover/leaver events, project status, sponsor state, service inventory, role-change record, workload retirement evidence.

Warning

Access can become stale even when the entitlement itself has not changed.

Privilege

Does the identity still need this level of access?

Evidence

Current job duty, privileged eligibility, actual task need, resource owner confirmation, recent use where appropriate.

Warning

A valid need for basic access does not automatically justify elevated privilege.

Resource sensitivity

How significant is the resource or action being reviewed?

Evidence

Application criticality, data classification, management-plane scope, privileged function, external-facing control.

Warning

Higher-impact access deserves stronger review evidence.

Ownership

Who is accountable for the identity, entitlement, resource, and final decision?

Evidence

Manager, sponsor, resource owner, application owner, privileged-role owner, service owner.

Warning

Unowned access should not be treated as normal.

Activity evidence

Does recent use support the stated purpose?

Evidence

Safe authentication, authorization, workload, privileged, or application activity metadata.

Warning

Recent use can support a review but does not by itself prove that access is justified.

Exception state

Is the access outside the preferred model, and if so, is that deviation still approved?

Evidence

Exception owner, reason, expiration, compensating control, target state, review record.

Warning

Expired exceptions should not become silent permanent access.

Evidence freshness

Is the review based on current enough information?

Evidence

Current identity state, recent owner confirmation, source health, role metadata, lifecycle event, review date.

Warning

Stale evidence should move the decision to Conditional or Unknown rather than Confirmed.

Governance Outcomes

Access Review Is More Than Approve or Reject

Confirm

Current evidence supports keeping the access unchanged.

Example: An active counselor still needs the counselor role for current student-support work.

Reduce

Some access remains justified, but the current scope or privilege is broader than needed.

Example: A reporting analyst keeps dashboard access but loses a sensitive export entitlement no longer required.

Remove

No current approved purpose remains.

Example: A former project administrator loses migration-admin eligibility after the project closes.

Reassign

Ownership or sponsorship must move to a new accountable person or team before access can continue.

Example: A service changes teams and the workload identity needs a new service owner.

Expire

Time-bounded access reaches its planned end state.

Example: A partner support identity expires when the support agreement or project window ends.

Review / Unknown

Available evidence is not sufficient for a confident continuation or removal decision.

Example: The resource owner is unknown and monitoring evidence is partial.

Accepted Risk

A known access weakness is explicitly approved for a bounded period by an authorized risk owner.

Example: A legacy service remains temporarily active under a documented exception while replacement work is underway.

Review Triggers

Access Should Be Reviewed When the World Changes

Scheduled review

Examples: Quarterly privileged-access review, semiannual application review, annual low-risk entitlement review.

Why it matters: Provides recurring confirmation even when no obvious change event occurs.

Role or team change

Examples: Counselor moves to operations, platform engineer changes teams, manager responsibility shifts.

Why it matters: Previously appropriate role memberships may no longer match current duties.

Employment or contractor change

Examples: Joiner, mover, leaver, contract end, leave status, rehire.

Why it matters: Identity lifecycle directly affects whether access should exist.

Project lifecycle

Examples: Migration starts, project milestone ends, temporary support closes, pilot is retired.

Why it matters: Project-bound roles and exceptions should end with the project unless re-approved.

Sponsor change

Examples: Partner sponsor leaves, guest sponsor changes, business owner no longer supports access.

Why it matters: External access should remain tied to a current internal owner.

Resource or application change

Examples: Application becomes more sensitive, data classification changes, service ownership moves, feature is retired.

Why it matters: Authorization appropriate for the old resource state may no longer be appropriate.

Privilege change

Examples: New admin function, elevated role, JIT eligibility, emergency-access assignment.

Why it matters: Higher impact should trigger stronger review.

Monitoring or policy finding

Examples: Unused high privilege, environment mismatch, stale attribute, unexpected authorization decision.

Why it matters: Evidence can reveal that the design no longer matches intended access.

Governance Principles

Eight Principles for Evidence-Based Access Certification

Review the relationship, not the label

An entitlement name like 'Analyst' or 'Admin' is not enough; reviewers need to know principal, resource, action scope, purpose, and lifecycle.

Review: Can another person explain exactly what the access allows?

Ownership is part of the decision

A manager may understand the user, while a resource owner understands the application or data impact.

Review: Are the right decision owners participating?

Recent use is supporting evidence, not automatic justification

An entitlement can be frequently used and still be overbroad or inappropriate.

Review: Does use match the approved business purpose?

Unused access deserves attention

Long-unused access may indicate stale need, but absence of use should be interpreted with business context.

Review: Is the access rarely used because it is emergency-only, or because it is obsolete?

Privilege should be reviewed more strongly

Administrative capability deserves more frequent and more evidence-rich review than routine low-impact access.

Review: Is privileged eligibility still tied to a current responsibility?

External access needs sponsor evidence

Partners and guests should not remain active without a current internal owner and business purpose.

Review: Who sponsors the identity today and when does it expire?

Exceptions need closure paths

A temporary risk acceptance should not turn into a permanent access model by default.

Review: What target state will close the exception?

Uncertainty should remain visible

When ownership, purpose, evidence, or lifecycle is unresolved, the review should say so.

Review: Is Unknown being hidden behind a Confirmed status?

Lifecycle Governance

Joiners, Movers, Leavers, Projects, Services, and Sponsors

Joiner

What baseline access is required for the new responsibility?

Decision focus: Minimum initial role, correct environment, sponsor/manager, resource approval, no inherited unnecessary access.

Mover

Which old access should be removed as new responsibilities are added?

Decision focus: Privilege reduction, old-team roles, project entitlements, resource ownership, conflicting duties.

Leaver

Which workforce, privileged, federation, partner, workload, and local access relationships must close?

Decision focus: Revocation timing, dependent ownership transfer, emergency identities, active sessions, shared resources.

Project end

Which temporary roles, exceptions, and privileged eligibility should expire?

Decision focus: Project-bound access, migration roles, temporary support, partner permissions, closure evidence.

Service retirement

Which workload identities, service accounts, roles, policies, and monitoring sources should retire with the service?

Decision focus: Non-human identity cleanup, local credentials, role removal, ownership transfer, archive evidence.

Sponsor loss

Should external access continue when the original sponsor is no longer accountable?

Decision focus: Reassign sponsorship, reduce access, expire identity, confirm current business need.

Vocabulary

Access Review and Governance Terms

Access review

A structured decision about whether an existing identity-to-resource relationship should continue, change, expire, or be removed.

Certification

A formal confirmation that reviewed access remains appropriate based on current evidence.

Entitlement

A role, permission, group membership, resource access, privileged eligibility, or other authorization granted to an identity.

Joiner/Mover/Leaver

Identity lifecycle events describing entry into an organization, change of responsibility, and departure.

Recertification

A recurring review that confirms whether existing access should still remain.

Resource owner

The person or team accountable for deciding appropriate access to an application, service, data resource, or privileged function.

Sponsor

The internal owner accountable for an external or guest identity's continued business need.

Residual risk

Risk that remains after controls, restrictions, compensating measures, or remediation have been applied.

Risk acceptance

An explicit authorized decision to tolerate a known residual risk for a defined period and purpose.

Remediation

The action taken after review to reduce, remove, expire, reassign, or otherwise correct access.

Evidence freshness

How current the identity, ownership, activity, lifecycle, and policy evidence is relative to the review decision.

Access owner

The accountable person or team responsible for the continued validity of a specific access relationship.

Fictional Access Review Register

Seven Northbridge Governance Decisions

REV-01ConfirmConfirmed

Counselor Workforce GroupStudent Services Portal

Entitlement

Counselor Role

Purpose

Current student-support workflow

Privilege

Standard application access

Lifecycle

Current counselor role

Owner

Student Services Application Owner

Activity

Recent role-appropriate use

Evidence

Current identity + role + authorization + owner confirmation

Exception

None

Next action

Review next quarter or on role change

Governance concern

Access should change immediately if counselor responsibility ends.

REV-02ReduceConfirmed

Reporting AnalystReporting Dashboard + Sensitive Export

Entitlement

Reporting Analyst + Sensitive Export

Purpose

Dashboard reporting remains current; export need ended

Privilege

Mixed standard + sensitive capability

Lifecycle

Role current

Owner

Analytics Product Owner

Activity

Dashboard active; sensitive export unused for 120 days

Evidence

Current role + activity + owner confirmation

Exception

None

Next action

Remove Sensitive Export; retain standard reporting

Governance concern

Keeping all access because some access is still needed would be overbroad.

REV-03RemoveBlocked

Former Migration Project AdministratorMigration Console

Entitlement

Migration Administrator Eligible

Purpose

Historical project; no current need

Privilege

Privileged eligibility

Lifecycle

Project closed

Owner

Migration Project Owner

Activity

No recent activation

Evidence

Current project closure + eligibility feed

Exception

None

Next action

Remove privileged eligibility and record closure

Governance concern

Unused privilege still remains available until eligibility is removed.

REV-04ReviewConditional

Scheduling Partner SupportScheduling Integration Console

Entitlement

External Integration Support

Purpose

Current partner support

Privilege

Narrow external support access

Lifecycle

Review due in 30 days

Owner

Integration Owner / Sponsor

Activity

Recent support activity

Evidence

Current sponsor + federation + app authorization

Exception

None

Next action

Sponsor must confirm continuation before expiration

Governance concern

Current activity does not replace the scheduled sponsor decision.

REV-05ConfirmConfirmed

Student Portal WorkloadStudent Support Database

Entitlement

Application Workload Access

Purpose

Current production application dependency

Privilege

Application-specific data operations

Lifecycle

Service active

Owner

Application Team + Data Platform

Activity

Current workload access

Evidence

Workload identity + deployment + database authorization logs

Exception

None

Next action

Review on application/dependency change

Governance concern

Service retirement must include workload-identity retirement.

REV-06Review / UnknownBlocked

Legacy Reporting AccountGenerated Report Storage

Entitlement

Historical Report Write Access

Purpose

Historical job; current need uncertain

Privilege

Legacy service permission

Lifecycle

No current review

Owner

Unknown

Activity

Intermittent

Evidence

Partial logs + stale entitlement metadata

Exception

No valid current exception

Next action

Resolve owner and business need; remove or formally govern

Governance concern

Activity alone does not justify unowned legacy access.

REV-07ReviewConditional

Emergency Recovery OperatorRecovery Administration

Entitlement

Emergency Admin Eligible

Purpose

Rare critical recovery

Privilege

Emergency privileged eligibility

Lifecycle

Eligibility current

Owner

Resilience + Security

Activity

One prior emergency use

Evidence

Activation/audit current; post-use review incomplete

Exception

Emergency session review condition

Next action

Complete post-use review before full certification

Governance concern

Emergency access may remain eligible, but unresolved prior use must stay visible.

Fake Dashboard

Northbridge Access Review Dashboard

Fictional certification, reduction, removal, and open governance decisions

Access relationships reviewed

7

Workforce, reporting, privileged, partner, workload, legacy, and emergency access

Confirm unchanged

2

Counselor and production workload access remain justified

Reduce / Remove

2

Sensitive export is reduced and obsolete migration privilege is removed

Open review conditions

3

Partner renewal, legacy ownership, and emergency post-review require closure

Fake SOC Alert

Obsolete Privileged Eligibility Still Active

Source: Fictional Access Governance Review • Time: 08:48

High Severity
REV-03 shows that a migration project is closed, yet privileged eligibility for the former project administrator remains assigned.
Defensive recommendation: Remove the obsolete privileged eligibility and record closure evidence. A new future project should require a new approved access decision.

Use vs. Need

Activity Evidence Helps, but It Does Not Decide the Review by Itself

Recent use can support a legitimate need

A counselor regularly using role-appropriate application functions is useful evidence when current job responsibility and resource ownership also support the access.

Recent use can also expose overbroad access

A user may actively use a capability that is convenient but no longer required. Access review asks whether use is authorized by current purpose, not merely whether use occurs.

Low use also needs context.

Emergency recovery access may be rarely used and still be legitimate. Long-unused ordinary or privileged access, however, may indicate stale need. Governance uses purpose and lifecycle to interpret activity correctly.

Fake Log Panel

Fictional Access Review Decision Log

training-log-viewer.log
[08:01] REV-01 counselor role=CURRENT purpose=CURRENT decision=CONFIRM state=CONFIRMED
[08:24] REV-02 reporting sensitive_export=UNUSED_120D decision=REDUCE state=CONFIRMED
[08:48] REV-03 migration-admin project=CLOSED eligibility=ACTIVE decision=REMOVE state=BLOCKED
[09:13] REV-04 partner sponsor=CURRENT review_due=30d decision=REVIEW state=CONDITIONAL
[09:37] REV-05 portal-workload service=ACTIVE dependency=CURRENT decision=CONFIRM state=CONFIRMED
[10:01] REV-06 legacy-report owner=UNKNOWN evidence=PARTIAL decision=UNKNOWN state=BLOCKED
[10:26] REV-07 emergency-admin post_review=PARTIAL decision=REVIEW state=CONDITIONAL

Training note: this is fake data for defensive analysis practice only.

Analyze the Evidence

Evidence Analysis: Reporting Access

The Reporting Analyst role is still current.
The analyst uses the standard Reporting Dashboard.
The Sensitive Export entitlement has not been used for 120 days.
The Analytics Product Owner confirms the export capability is no longer required.
Standard dashboard access is still needed.

What is the strongest decision for REV-02?

Governance Anti-Patterns

Eight Ways Access Reviews Become a Checkbox Exercise

1

Rubber-stamp certification

Why it fails: Reviewers approve large access lists without examining purpose, scope, privilege, or lifecycle.

Better approach: Require enough context to make a real decision for each material access relationship.

2

Review by entitlement name only

Why it fails: Labels such as Analyst or Admin hide what the role actually permits.

Better approach: Show resource, action scope, privilege, environment, and owner.

3

Usage equals justification

Why it fails: Frequently used access is automatically kept even when the scope is broader than the business need.

Better approach: Treat activity as supporting evidence, not proof of authorization need.

4

Unused means remove automatically

Why it fails: Rare emergency or seasonal access can be legitimate even when it is seldom used.

Better approach: Interpret low use together with purpose, lifecycle, and resource impact.

5

Manager reviews privileged access alone

Why it fails: The manager may understand the employee but not the technical impact of the admin role.

Better approach: Include privileged-role or resource owners in higher-impact decisions.

6

External access has no sponsor review

Why it fails: Partner access remains active after the internal business relationship changes.

Better approach: Require current sponsorship and expiration or recertification.

7

Exception renewal with no target state

Why it fails: Temporary risk becomes permanent because every review simply extends the same exception.

Better approach: Require remediation target, closure owner, and bounded expiration.

8

Unowned access gets auto-confirmed

Why it fails: Nobody can explain who is accountable for the entitlement or resource.

Better approach: Move the relationship to Unknown/Blocked until ownership is resolved.

Scenario Decision Lab

Scenario Decision Lab 1 — Reduce, Don't Rubber-Stamp

A reporting analyst still needs the dashboard role, but the resource owner confirms that a separate sensitive-export entitlement is no longer required.

Scenario Decision Lab

Scenario Decision Lab 2 — Active but Unowned Legacy Access

A legacy reporting account still performs occasional production work. The current owner is Unknown, evidence is partial, and no valid current exception exists.

Safe Fictional Lab

Build an Access Review Decision Register

Use fictional identities, entitlements, resources, owners, lifecycle records, and synthetic activity evidence only. Do not modify any real access.

1

Create at least fifteen fictional access-review records.

2

Give every record a stable REV ID.

3

Record principal and principal type.

4

Record resource/application.

5

Record entitlement or privileged eligibility.

6

State current business or technical purpose.

7

Record privilege level.

8

Record lifecycle state.

9

Record identity owner, manager, sponsor, or service owner.

10

Record resource/entitlement owner.

11

Record recent activity evidence where appropriate.

12

Record evidence freshness.

13

Record exception or risk-acceptance status.

14

Choose Confirm, Reduce, Remove, Reassign, Expire, Review, or Accepted Risk.

15

Record the reason for the decision.

16

Record remediation or next action.

17

Record closure owner.

18

Record review/change trigger.

19

Include at least three workforce examples.

20

Include at least three privileged examples.

21

Include at least two external/partner examples.

22

Include at least two workload identities.

23

Include at least two temporary/project examples.

24

Include at least one unowned legacy entitlement and keep it Blocked.

25

Include at least one Accepted Risk record with owner, expiration, and target state.

Lab boundary

This is a fictional governance exercise. Do not inspect private access lists, remove real users, change group membership, alter roles, or modify any live identity or authorization system.

Analyze the Evidence

Evidence Analysis: Legacy Reporting Access

The legacy account still performs intermittent production activity.
The current owner is Unknown.
The current business need is uncertain.
Evidence is Partial.
No valid current exception exists.

What is the strongest governance state for REV-06?

Advanced Challenge

Run a Fictional Enterprise Access Review Board

A fictional organization has workforce roles, partner guests, privileged eligibility, workloads, temporary project access, emergency identities, and several legacy exceptions. Design a review board that can make consistent decisions without rubber-stamping everything.

1

Identity lifecycle evidence

2

Business purpose evidence

3

Resource sensitivity

4

Privilege level

5

Manager/sponsor input

6

Resource-owner input

7

Workload/service ownership

8

Activity evidence

9

Source health

10

Exception state

11

Risk owner

12

Confirm/Reduce/Remove logic

13

Reassignment logic

14

Expiration logic

15

Remediation ownership

16

Closure evidence

A mature review board should preserve legitimate access, reduce unnecessary scope, remove stale relationships, escalate uncertainty, and document who owns each follow-up action.

Defender Habits

A13.8 Defender Checklist

Skill Check

Seven Questions

Check Your Understanding

A13.8 Mini Quiz: Access Reviews and Governance

Choose your answers first. Explanations appear only after submission.

1. What is the main purpose of an access review?

2. A reporting analyst still needs dashboard access but no longer needs sensitive export capability. What is the strongest outcome?

3. Why should recent activity not automatically justify access?

4. A project ended but privileged eligibility remains assigned. What is the strongest review decision?

5. What should happen when an external partner's review date approaches?

6. What is strongest for an unowned legacy entitlement with partial evidence?

7. What makes a risk acceptance stronger?

Portfolio Prompt

Portfolio Build — Access Review Decision Register

Create the eighth artifact for your A13 Enterprise Identity and Zero-Trust Review: a fictional Access Review Decision Register with at least fifteen records. Include REV ID, principal, principal type, resource, entitlement, purpose, privilege, lifecycle, identity owner/manager/sponsor/service owner, resource owner, activity evidence, evidence freshness, exception/risk state, decision, rationale, remediation, closure owner, status, and next review/change trigger.

Use Confirm, Reduce, Remove, Reassign, Expire, Review, and Accepted Risk outcomes.
Include workforce, privileged, external, workload, and temporary access.
Treat activity as supporting evidence rather than automatic justification.
Keep Unknown ownership and stale evidence visible.
Include at least one explicit Accepted Risk with expiration and target state.
Use fictional provider-neutral records only.

Confidence / Readiness Reflection

Are You Ready for A13.9?

A13.9 moves into Balancing Security and Usability. Before continuing, make sure you can explain how an access review can preserve necessary work while reducing unnecessary friction and privilege.

1

I can explain access review as a lifecycle governance decision.

2

I can distinguish Confirm, Reduce, Remove, Expire, and Review outcomes.

3

I can explain why activity does not automatically justify access.

4

I can explain how privileged, external, and workload access need different evidence.

5

I can explain how exceptions and residual risk should remain visible.

Portfolio Build Guide

How to Make the Access Review Register Look Professional

Show the real entitlement

Do not stop at job title. Record the actual resource, role, privilege, or workload permission under review.

Show purpose and lifecycle

Make the current reason for access and the event that should change or end it visible.

Show multiple owners

Manager, sponsor, service owner, privileged-role owner, and resource owner may have different responsibilities.

Show evidence quality

Current, Partial, Stale, Missing, and Unknown evidence should affect review confidence.

Show the decision clearly

Use Confirm, Reduce, Remove, Reassign, Expire, Review, or Accepted Risk rather than vague notes.

Show remediation

Every reduction, removal, reassignment, or exception should have an owner and closure state.

Keep legacy uncertainty visible

Do not certify an account simply because removing it might be inconvenient.

Connect forward

A13.9 will evaluate how strong controls can remain usable, understandable, and proportionate.

Key Takeaways

What You Should Remember

1.Access review asks whether a current identity-to-resource relationship should still exist now.
2.Strong reviews consider purpose, privilege, resource sensitivity, ownership, lifecycle, evidence, and exceptions.
3.Review outcomes can Confirm, Reduce, Remove, Reassign, Expire, or move access to Review/Unknown.
4.Activity is useful evidence but does not prove that access is justified.
5.Unused access can be stale, but rare emergency access may still be legitimate.
6.Privileged eligibility should be removed when the responsibility that justified it ends.
7.External identities require current sponsorship and lifecycle review.
8.Workload access should be reviewed when services, dependencies, or ownership change.
9.Risk acceptance should be explicit, bounded, and linked to residual risk and a target state.
10.The Access Review Decision Register will support A13.9 Balancing Security and Usability.

Lesson Safety Boundary

Access-review learning does not require changing real accounts

Do not remove real users, alter permissions, change roles, inspect private identity exports, or modify live access-control systems. All identities, entitlements, review evidence, and governance decisions in this lesson are fictional and defensive.

Lesson Complete

A13.8 Access Reviews and Governance Complete

You now have an access-governance model built around current purpose, lifecycle, privilege, ownership, activity evidence, sponsorship, exceptions, residual risk, remediation, and closure. Next, A13.9 focuses on Balancing Security and Usability.