Skip to main content
Joinly by KoppelHet

User access review

A user access review per client, without a spreadsheet

The classic access review is an export sent round to managers who do not recognise the group names. What comes back is a column of ticks. With Joinly you review per client what is actually set up, next to what was intended, and for every difference you see where it comes from.

The short answer

A user access review is the periodic check that people still have the access that belongs to their work. Joinly puts, per person, the access someone actually has next to the access that belongs to their job, and shows why someone has something: through a role, an HR attribute, an exception with an end date, or outside Joinly. You run the review per client, on request or on a schedule, and record what you decide.

Why the annual review fixes so little

The export is out of date the moment it is sent. The manager who receives it sees group names that mean nothing to them, and so approves everything. And nobody can explain why someone has access to something. The result is a document for the auditor, and the environment is no better for it.

What should be, next to what is

Joinly works out per person which access there should be based on roles, HR attributes and granted exceptions, and fetches what is actually in Entra ID alongside it. The difference is your work queue: access that is missing, and access that is there but should not be.

De toegangsevaluatie in Joinly: feitelijke naast bedoelde toegang

Why does someone have this access?

For every piece of access, Joinly records the reason: a role, an HR attribute, an exception with a reason and an end date, or something granted outside Joinly. That last group is usually the most interesting, because that is where the access sits that nobody remembers the reason for.

Per client, as often as needed

You review one person after a change of role, a department after a reorganisation or a whole client in one go, on request or on a schedule. You apply the result straight away or after someone has checked it. What you decide goes into the audit log, and that is the document your client hands to their auditor.

User access review

Frequently asked questions

  • What is a user access review?

    A periodic check that people still have the access that belongs to their work. Access that is no longer needed is revoked or justified again.

  • How often should you review access rights?

    ISO 27001 asks for access rights to be reviewed at regular intervals and does not set a fixed period. Many organisations do it annually or quarterly, and also after a reorganisation or a change of role.

  • Can you look first without revoking anything?

    Yes. The review shows the difference before you apply anything. You decide what happens, straight away or after someone has checked it.

  • What do you do with access granted outside Joinly?

    You see it separately in the review. You revoke it, or you record it as an exception with a reason and an end date.

  • What does the auditor get?

    The audit log of the review: what was looked at, what was decided and who did it.

Account management for your clients as a standard service?

In an introduction we walk through how Joinly would work for your clients: which HR systems, which environments and where you want to start. We agree the terms of a partnership in the same conversation.

Book an introduction