Let's talk
Access Rights Review

Know who has access and what needs to change.

People leave, roles change and temporary access can stay in place. We review who can use your systems, check what they still need and give you a clear list of recommended changes.

Best fit

When it helps

When access has become difficult to track, or the review keeps slipping behind other priorities.

  • People have left. Has their access gone too?

    Former employees or contractors may still appear in some systems. You need to know whether their accounts remain active and what they can reach.

    • Compare available account lists with current staff and contractor records.
    • Identify remaining access associated with people who have left.
    • Confirm exceptions with system owners and recommend changes.
  • Roles have changed. Access has built up.

    People have moved between projects or taken on different work. Permissions granted along the way may no longer match what they do today.

    • Review access against current roles and working needs.
    • Identify permissions that need an explanation or no longer appear necessary.
    • Record what should stay, what should change and what needs a decision.
  • External access is hard to track

    Suppliers and temporary collaborators have helped over time. It is no longer clear who still needs access or who can confirm that need.

    • Identify external users within the agreed systems.
    • Check the purpose, business contact and continuing need for their access.
    • Flag unexplained access and record who needs to resolve it.
  • You know a review is needed. Time is the problem.

    Your team understands the systems, but comparing account lists and following up with owners keeps losing out to product work and daily demands.

    • Use existing account records and any review work already completed.
    • Prepare the access list and coordinate checks with the relevant people.
    • Hand over prioritized findings with decisions and open questions recorded.
Scope & deliverables

Access findings, with clear next steps.

We review the systems and account types agreed with you, check the findings with the relevant owners and document the changes to consider.

What's included

Check who can do what, and why.

  • Preparation using available account lists, role information and previous access reviews.
  • An access list for the agreed systems and account types, covering staff, contractors and other relevant users.
  • Comparison of current access with people's roles and business needs.
  • Checks with relevant system owners to confirm findings and identify exceptions.
  • Prioritized recommendations, recorded decisions and a findings walkthrough.
What you receive

Findings your team can act on.

  • A dated access list showing the users and permissions reviewed in the agreed systems.
  • Prioritized findings covering access that is no longer needed, unexplained or awaiting confirmation.
  • Recommended changes, with the reason for each and decisions recorded for follow-up.
  • A record of coverage, missing information, exceptions and unresolved questions.
Out of scope

Beyond the review and recommendations.

Any further work is optional and agreed separately.

  • Removing accounts, changing permissions or implementing an identity platform.
  • A detailed assessment of safeguards around powerful accounts, such as emergency access and activity recording.
  • Ongoing access administration, continuous monitoring or certification of the wider security setup.
Process

How it works

We prepare the review, coordinate the checks and document the findings. Your team helps confirm the access people still need.

  1. Agree the scope and gather existing records

    We agree the systems, account types, review date, price and timing. We work from available account lists and role information, arranging any further access or input with the relevant people.

  2. Build and compare the access list

    We bring the available records together and compare permissions with current roles and needs. We flag access that appears unnecessary, cannot be explained or needs closer checking.

  3. Confirm the findings with system owners

    We follow up with the people who know the systems and the work they support. We check the reasons for access, record exceptions and separate confirmed findings from unanswered questions.

  4. Hand over the recommendations

    We walk you through the priorities, proposed changes and decisions still needed. Your team receives the access list and findings record to guide the follow-up.

Get in touch

Unsure who still has access?

An informal 30-minute call to discuss your concerns and see whether an Access Rights Review is the right fit.