User access review
A user access review is a periodic check in which the right people confirm, grant by grant, that existing access is still needed, and revoke what is not, producing evidence an auditor can rely on.
A user access review (also called an access certification or recertification) asks a simple question at scale: for every grant an identity holds, does someone accountable confirm it is still needed? Frameworks like SOC 2 and ISO 27001 expect them on a regular cycle, which is why most teams meet them first as an audit requirement, but their real job is catching privilege creep before it becomes exposure.
Why spreadsheet reviews fail
The traditional cycle exports every account to a spreadsheet, mails it to managers, and chases signatures for weeks. It fails in predictable ways: reviewers rubber-stamp lists too long to read, the export is stale before the review closes, decisions are recorded against rows rather than the underlying grants, and revocations become tickets that may or may not happen. The result is evidence of a process, not evidence of control.
What a working review looks like
Reviews work when they are scoped by entitlement rather than by seat, reach reviewers where they already work, execute revocations automatically when a reviewer says no, and close with a snapshot tying every decision to the grant it applied to. Ploy's access reviews run this way, with Luna doing the reading and flagging the grants worth a human's attention.