SOP templatesIT

User Access Review SOP Template

A ready-to-use SOP for periodically certifying that user access to systems and data still matches each person's current role.

FreeNo sign-upWord, PDF, Excel & CSV
Ilia PirozhenkoReviewed by Ilia Pirozhenko, Founder, Perfect WikiUpdated September 15, 202612 steps4 roles3 min read
Standard operating procedureSOP-IT-008 ยท Rev 1.0
Owner
IT Security Manager
Effective date
September 15, 2026
Review cycle
Every 6 months

1.Purpose

To periodically verify that user access to systems and data remains appropriate, removing excess or stale permissions and confirming access still matches each person's current role.

2.Scope

Applies to scheduled reviews of user accounts, group memberships and application access across in-scope systems, including leavers and role changes. Initial account creation and password resets are covered by separate procedures.

Definitions

Access review cycle
A scheduled point-in-time review of who has access to a given system.
Entitlement
A specific permission or group membership granted to a user account.
Segregation of duties
A control that prevents one person from holding two conflicting entitlements, such as creating and approving the same transaction.
Stale account
An account with no recent login activity that may no longer be needed.

3.Responsibilities

System Administrator
Generates access reports, revokes or adjusts access, and disables stale accounts.
IT Security Manager
Coordinates the review cycle, resolves flagged conflicts, and reports results.
Application Owner
Certifies whether each user's access to their application is still needed.
People Manager
Confirms which team members still need access based on current role and team changes.

RACI matrix

ActivitySystem AdministratorIT Security ManagerApplication OwnerPeople Manager
Generate and distribute the access reviewRR/AII
Certify user access decisionsICR/AR
Revoke or adjust accessR/ACII
Resolve segregation of duties conflictsCR/ACI
Report review completion to leadershipIR/AII

R = Responsible, A = Accountable, C = Consulted, I = Informed

4.Materials and PPE

Materials, tools and systems

  • โ†’Identity provider reporting tool
  • โ†’Access review spreadsheet or template
  • โ†’Segregation of duties matrix
  • โ†’Review calendar
  • โ†’Reviewer sign-off or attestation record

5.Procedure

  1. 5.1

    Generate the access review report

    System Administrator

    The System Administrator exports a list of users and their entitlements for each system in scope from the identity provider.

  2. 5.2

    Distribute the review to reviewers

    IT Security Manager

    The IT Security Manager sends each access list to the relevant Application Owner or People Manager, with a deadline for completing the certification.

  3. 5.3

    Certify each user's access

    Application Owner

    The Application Owner or People Manager reviews the list and marks each user's access as still needed, to be modified, or to be removed.

    Checkpoint: Every account on the list receives an explicit decision; none are left blank or skipped.

  4. 5.4

    Flag segregation of duties conflicts

    IT Security Manager

    The IT Security Manager reviews certified decisions against the segregation of duties matrix and flags any user holding conflicting entitlements.

  5. 5.5

    Identify leavers and role changes

    System Administrator

    The System Administrator cross-checks the access list against recent departures and internal role changes to catch access that should already have been removed.

    Warning: Any active account for a departed employee is a priority removal and should not wait for the next scheduled review.

  6. 5.6

    Revoke or adjust access

    System Administrator

    The System Administrator implements each reviewer's decision, removing or adjusting entitlements as certified.

  7. 5.7

    Disable stale accounts

    System Administrator

    The System Administrator disables or removes accounts with no recent login activity, after confirming the account is not a required service account.

    Checkpoint: Each stale account is confirmed as not a required service account before it is disabled.

  8. 5.8

    Document review decisions

    IT Security Manager

    The IT Security Manager records each reviewer's decisions and any supporting notes in the access review record.

  9. 5.9

    Escalate contested decisions

    IT Security Manager

    The IT Security Manager reviews and makes the final call on any decision the reviewer and account holder disagree about.

  10. 5.10

    Compile completion and sign-off

    IT Security Manager

    The IT Security Manager compiles the completed review results and collects sign-off confirmation from each reviewer.

  11. 5.11

    Report to leadership

    IT Security Manager

    The IT Security Manager reports the review's completion rate and notable findings, such as segregation of duties conflicts, to leadership.

  12. 5.12

    Schedule the next cycle

    IT Security Manager

    The IT Security Manager schedules the next access review cycle and updates the review calendar.

6.Quality checks

  • โ†’Every account on the review list receives an explicit reviewer decision.
  • โ†’Access for departed employees is revoked promptly rather than waiting for the next cycle.
  • โ†’Segregation of duties conflicts are documented and resolved.
  • โ†’Each review cycle has a signed-off completion record.

7.Records

  • โ†’Access review report
  • โ†’Reviewer certification or sign-off
  • โ†’Segregation of duties exception log
  • โ†’Revocation confirmation

8.KPIs

  • โ†’Access review completion rate
  • โ†’Average time to revoke access after a role change or departure
  • โ†’Number of stale or excess access findings per cycle
  • โ†’Percentage of accounts with no reviewer response

9.Common mistakes

  • โ†’Rubber-stamping the review without checking each account individually.
  • โ†’Missing internal role changes because the focus is only on leavers.
  • โ†’Leaving a flagged segregation of duties conflict unresolved after the review closes.
  • โ†’Not revoking access promptly once a reviewer marks it for removal.

10.Revision history

RevisionDateDescriptionReviewed by
1.0September 15, 2026Initial releaseIlia Pirozhenko

This is a template. Adapt it to your organization, equipment and local regulations before use.

Ask this SOP

Nobody opens a PDF in the middle of a task. They ask.

Add this SOP to Perfect Wiki and your team gets answers in the chat app they already use, with a link to the exact step. Ask from ChatGPT, Claude or Copilot too.

Perfect Wiki AIExample answer

An employee moved from finance to marketing last month, do we still need to review their old finance access?

Yes. Step 5.5 treats internal role changes the same as departures: their old finance entitlements should be checked and removed if no longer needed, not carried forward untouched.Source: step 5.5 ยท Identify leavers and role changes
Ask your own question about this SOPโ€ฆSign up to keep asking
Word file vs Perfect Wiki

A downloaded SOP starts going out of date the day you save it.

Screen recorders like Scribe and Tango capture clicks. Perfect Wiki holds the whole procedure, including your recorded guides, and answers questions about it.

Word or PDFPerfect Wiki
Finding itDig through folders and email threadsAsk in Teams, Slack, kChat or Mattermost
Keeping it currentEmail a new version and hopeEdit once with AI, everyone sees the update
Everything in one placeText and imagesEmbed Scribe and Tango guides, SharePoint files and videos
Who can change itAnyone with the fileEditors you choose, everyone else reads
Common questions

Frequently asked questions

Didn't find what you're looking for? Contact our support โ†’

Your SOP library

Keep every SOP where your team can ask it.

Perfect Wiki is the knowledge base for Microsoft Teams, Slack, kChat and Mattermost. Store your SOPs, embed your Scribe and Tango guides, and let AI answer questions with a link to the right step.

No credit cardSetup in under 10 minutesCancel anytime