User access review for small teams: the quarterly pass that proves nobody kept a key

Every audit conversation about access eventually lands on the same question, and it is not a technical one: who still has access to what, and how do you know? The joiner part of access is usually handled — there is a ticket, an onboarding list, an onboarding checklist. The leaver part has its own page (access request & offboarding). What rots in the middle is the staying: the support contractor moved to another client but kept the admin seat, the manager's old backup login survived the promotion, the shared drive permission granted "just for the audit" in March is still wide open in September. A quarterly user access review is the pass that finds the rot — and it is the single cheapest piece of evidence SOC 2, ISO 27001, and every customer security questionnaire will ask you for. This page is the walk.

1. Why the review exists before how to run it

2. Build the people list before the systems list

3. Inventory the systems list — include the ones without a dashboard

4. The walk: every person against every system they touch

5. The five findings you will find on the first pass

6. Fix same-day, log the decision, skip the re-education

7. File the evidence the auditor (or the customer) will ask for

8. The quarterly rhythm, and the part to automate

A user access review is one list of people, one list of systems, and a walk that leaves a dated decision on every intersection: revoke the orphans, downgrade the role creep, name the shared logins, kill the stale contractor seats, and verify the break-glass nobody uses. Fix same-day, file the export with a signature, and repeat in the same week every quarter. The Ops Starter Kit ($14) puts the review sheet and the evidence folder structure on fill-in-the-blank templates, and the Automation Starter Pack ($19) schedules the quarterly review nudge and the user-list pulls so the walk starts from data instead of memory.