The periodic access review, a reviewer confirming a list of memberships, is a fixture of governance programs. The comparison is not against reviewing, which compliance requires, but against reviewing blind: certifying direct memberships while effective access flows through structure the reviewer never sees.
What manual reviews certify#
A reviewer approving a user's membership in a named group certifies one edge. What the organization needs certified is the consequence: everything that membership grants through the group's own nesting and assignments. The gap between edge and consequence is precisely the transitive structure, invisible in review interfaces built on flat lists.
The predictable failure modes#
Blind reviews fail the same ways everywhere:
- Rubber stamping: reviewers approve what they cannot evaluate, and the review becomes a ritual.
- Renewal of the invisible: access through nested paths is never presented, so it is never questioned.
- No delta: each cycle reviews from scratch instead of focusing on what changed since last time.
VisualizerEngine
What structural visibility adds
Reviews conducted with the graph in view evaluate consequences: the paths behind each membership, the licenses that flow along them, and, via snapshot diffs, exactly what changed since the previous review, which is where attention belongs. Exports with provenance metadata make the review's evidence pack verifiable.