An access review is a recurring process in which a responsible person certifies that a set of users should still hold a set of access. Compliance frameworks require them; their value depends entirely on whether the reviewer can see what the access actually amounts to.

The certification gap#

Reviews present memberships, but consequences live in structure: a certified membership in one group carries everything that group reaches through nesting. A reviewer approving the visible edge implicitly approves the invisible closure, which is how reviewed tenants still accumulate stale effective access.

What makes a review meaningful#

Three inputs turn certification from ritual into control:

  • Consequence visibility: what each membership grants, including transitively.
  • Change focus: what is new since the last review, so attention lands where risk moved.
  • Evidence: an exportable record of what was reviewed and decided, with provenance.

VisualizerEngine

Reviews with VisualizerEngine

The graph shows what each membership reaches, snapshot diffs isolate what changed between review cycles, and compliance exports carry provenance metadata and an integrity trailer for the evidence pack. The Auditor role gives reviewers read-only sight without admin rights.