The quarterly access review that eats a week
Every quarter, the same spreadsheets, the same chasing, the same result, and an attestation that describes a state which has already changed by the time it is signed.
What actually happens
The access review is not a control. It is a snapshot of a moving system, taken slowly, signed late, and filed.
Entitlements are exported from several systems. They are formatted into spreadsheets, split by manager, and emailed out with a deadline.
Managers are asked to attest that each person on their list should have each entitlement on it. Many of those entitlements are named in a way that means nothing outside the team that created them, so the honest answer for a meaningful share of rows is that the manager cannot tell.
Chasing consumes most of the elapsed time. Responses arrive in different formats, get collated by hand, and produce a set of revocations that then have to be raised individually.
By the time the attestation is signed, weeks have passed. Access has been granted and revoked throughout that period, because the business did not stop while the review ran. The document accurately describes a state that no longer exists.
The auditor question that this process answers poorly is not "were entitlements appropriate on the review date". It is "how do you know they were appropriate on every other day", and a quarterly snapshot has no answer to that at all.
A quarterly review tells you about four days a year. The other three hundred and sixty-one are covered by the assumption that nothing interesting happened.
The same quarter, two ways
This is measured in person-weeks and in evidence coverage, not in minutes.
Illustrative, not measured. The times below model a scenario built from the patterns we see in production estates. They are not timings recorded at a named customer. The point is the shape of the clock, not the totals: check it against your own last ten incidents.
Today, exported, mailed and chased
- Week 1Entitlements exported from several systems. Spreadsheets built and split by manager.
- Week 1 ↓ Week 3WaitingChasing. Partial responses in inconsistent formats. Many rows attested without confidence.
- Week 3Responses collated by hand. Revocation list produced.
- Week 3 ↓ Week 5WaitingRevocations raised individually. Dependencies unclear, so several are deferred.
- Week 5Attestation signed. It describes the state as at Week 1.
- Week 5+No evidence exists for any day between this review and the next.
~5 weeks elapsed · covering one day of evidence
With evidence assembled continuously
- Every dayEntitlement state, grants, revocations and sampled actual usage recorded continuously as they happen.
- On grantEach new entitlement recorded against its justification, the change record and the requesting context.
- ContinuouslyEntitlements the account never exercises surfaced with usage evidence rather than with a policy comparison.
- ContinuouslyManager-readable descriptions resolved from the entitlement definition, so attestation is answerable.
- Review dayReview is a report over a record that already exists. Exceptions are the only rows requiring a decision.
- Any dayAn auditor asking about a date between reviews gets an answer rather than an assumption.
Review becomes a report · evidence covers every day, not four
The person-weeks are the number your finance team will engage with, and it is easy to compute: the effort your last review consumed, multiplied by your review frequency, plus the manager time that never appears in the project plan.
The coverage argument is the one your auditor will engage with. Periodic attestation produces evidence for the review date and no others, and that gap is structural rather than a matter of doing the review better.
The mechanism is recording entitlement changes as events rather than reconstructing them as a report. A grant recorded at the moment it happens, with its justification and change record attached, is evidence. The same grant reconstructed from logs three months later is an inference.
The honest limitation: continuous evidence does not remove the manager decision, and it should not. What it removes is the rows where the manager had no basis to decide, by attaching usage evidence and a readable description to each entitlement.
Why the number is what it is
The person-weeks are the number your finance team will engage with, and it is easy to compute: the effort your last review consumed, multiplied by your review frequency, plus the manager time that never appears in the project plan.
The coverage argument is the one your auditor will engage with. Periodic attestation produces evidence for the review date and no others, and that gap is structural rather than a matter of doing the review better.
The mechanism is recording entitlement changes as events rather than reconstructing them as a report. A grant recorded at the moment it happens, with its justification and change record attached, is evidence. The same grant reconstructed from logs three months later is an inference.
The honest limitation: continuous evidence does not remove the manager decision, and it should not. What it removes is the rows where the manager had no basis to decide, by attaching usage evidence and a readable description to each entitlement.
The mechanism is recording entitlement changes as events rather than reconstructing them as a report.
Who decides to press go
Revoking access as a result of a review is still a change to a live account, and it is gated the same way any other entitlement change is.
Recording, correlating, surfacing unused entitlements and assembling attestation evidence all run under policy. None of it changes an entitlement.
Each revocation is raised with the usage evidence, the dependency analysis and the rollback path attached, and waits for the accountable manager to approve.
The review does not become automatic. It becomes a decision about exceptions rather than a data collection exercise with a decision at the end.
Entitlement grants, revocations and usage recorded continuously across the estate as they occur, rather than exported periodically.
Each entitlement correlated against its justification, the originating change record, current service ownership and sampled actual usage.
Unused entitlements surfaced with evidence. Revocations raised individually for the accountable manager with dependency analysis and rollback.
Entitlement descriptions resolved into manager-readable form so attestation is answerable. Evidence coverage maintained for every day rather than for review dates.
This is a platform capability, not a published customer deployment for this exact scenario. The mechanism, which is correlated investigation followed by governed MOP execution with pre-check, post-check, rollback and approval gating, is running in production today; see governed day-2 operations across 2,000+ nodes, infrastructure observability across a large server estate and closed-loop network automation. The timings shown are modelled, not measured.
If the action carries no service impact
Recording, correlating, surfacing unused entitlements and assembling attestation evidence all run under policy. None of it changes an entitlement.
If it revokes access
Each revocation is raised with the usage evidence, the dependency analysis and the rollback path attached, and waits for the accountable manager to approve.
What Sentinel did, step by step
- ObserveEntitlement grants, revocations and usage recorded continuously across the estate as they occur, rather than exported periodically.
- InvestigateEach entitlement correlated against its justification, the originating change record, current service ownership and sampled actual usage.
- ActUnused entitlements surfaced with evidence. Revocations raised individually for the accountable manager with dependency analysis and rollback.
- OptimizeEntitlement descriptions resolved into manager-readable form so attestation is answerable. Evidence coverage maintained for every day rather than for review dates.
Bring us your last access review
We will show you how many rows a manager had no basis to attest.