User access review
A user access review per client, without a spreadsheet
The classic access review is an export sent round to managers who do not recognise the group names. What comes back is a column of ticks. With Joinly you review per client what is actually set up, next to what was intended, and for every difference you see where it comes from.
The short answer
A user access review is the periodic check that people still have the access that belongs to their work. Joinly puts, per person, the access someone actually has next to the access that belongs to their job, and shows why someone has something: through a role, an HR attribute, an exception with an end date, or outside Joinly. You run the review per client, on request or on a schedule, and record what you decide.
Why the annual review fixes so little
The export is out of date the moment it is sent. The manager who receives it sees group names that mean nothing to them, and so approves everything. And nobody can explain why someone has access to something. The result is a document for the auditor, and the environment is no better for it.
What should be, next to what is
Joinly works out per person which access there should be based on roles, HR attributes and granted exceptions, and fetches what is actually in Entra ID alongside it. The difference is your work queue: access that is missing, and access that is there but should not be.

Why does someone have this access?
For every piece of access, Joinly records the reason: a role, an HR attribute, an exception with a reason and an end date, or something granted outside Joinly. That last group is usually the most interesting, because that is where the access sits that nobody remembers the reason for.
Per client, as often as needed
You review one person after a change of role, a department after a reorganisation or a whole client in one go, on request or on a schedule. You apply the result straight away or after someone has checked it. What you decide goes into the audit log, and that is the document your client hands to their auditor.
User access review
Frequently asked questions
What is a user access review?
A periodic check that people still have the access that belongs to their work. Access that is no longer needed is revoked or justified again.
How often should you review access rights?
ISO 27001 asks for access rights to be reviewed at regular intervals and does not set a fixed period. Many organisations do it annually or quarterly, and also after a reorganisation or a change of role.
Can you look first without revoking anything?
Yes. The review shows the difference before you apply anything. You decide what happens, straight away or after someone has checked it.
What do you do with access granted outside Joinly?
You see it separately in the review. You revoke it, or you record it as an exception with a reason and an end date.
What does the auditor get?
The audit log of the review: what was looked at, what was decided and who did it.
- Joinly for MSPsFor an MSP, every joiner and leaver at a client is a ticket, a checklist and work that is hard to bill for. Joinly picks up those changes from your client's HR system and handles accounts, groups, licences and access automatically. For all your clients, from one login, with each client in its own environment.
- Access control matrix per clientAlmost every organisation has an access control matrix somewhere: a spreadsheet with job roles in the rows and systems in the columns. And almost everywhere it lags behind what is actually set up. With Joinly the matrix becomes the place access comes from, so it never lags behind again.
- Cleaning up stale accountsAlmost every environment has accounts that no longer belong there: of people who left long ago, of a test that was never finished, of a connection nobody remembers. As long as they are there, they are a way in. This is how you find them, and how you make sure they do not come back.
- ISO 27001 and access controlAccess control always comes up in an ISO 27001 audit. The standard asks for a policy, and it also asks you to show that the policy is carried out. If you are the MSP doing the management, that question lands with you.
Account management for your clients as a standard service?
In an introduction we walk through how Joinly would work for your clients: which HR systems, which environments and where you want to start. We agree the terms of a partnership in the same conversation.
Book an introduction