Home Services About Blog Contact 📞 1-800-890-6133

Access Reviews Should Default to Revoke

By Brian Shad  ·  Pro Link Systems  ·  October 01, 2026

Ask your IT lead who still has access to the shared finance folder, and you will have an answer by the end of the day. Put the same question about which connected applications hold standing permission to read every mailbox in the tenant, and the answer takes a week — if it arrives at all.

That asymmetry is the problem with the quarterly access review as most companies still run it. The exercise was designed for a world where access meant a person and a folder. Today it runs against an environment where a growing share of the things holding permissions are not people at all, and where the people who do hold permissions were granted most of them for jobs they no longer perform.

The answer is not a longer checklist. Change what the review reviews, and change who signs it.

The identities nobody counted

Walk through what accumulates in a hypothetical 150-seat environment. User accounts, obviously. Underneath them sits everything that was never on a staff list:

Not one of these has a last day. Offboarding, the single lifecycle event that reliably removes access anywhere, simply does not apply to them.

Agents belong on that list as well. The common design pattern for AI assistants embedded in business software is delegation: the assistant acts with the permissions of the identity that invoked it. This is analysis rather than prediction, but it follows directly from how delegated permission models work. An over-permissioned user is a risk bounded by one person's judgment, attention, and working hours. That same user wired to an agent becomes an over-permissioned process — one that can traverse everything the identity can reach, quickly and repeatedly, without the social friction that stops most people from opening a folder they know is not theirs.

Deploy Microsoft 365 Copilot or any agent framework on a tenant whose permissions have never been pruned, and you have not created a new exposure. You have made an old one far easier to exercise.

Access accumulates and almost nothing removes it

Consider how permission actually grows. Someone joins the finance team and receives the finance group. A cover assignment during a colleague's leave adds payroll. A move into operations adds the operations group — and nobody removes finance, because removal requires a person to notice and a person to decide, and neither is anyone's job. A vendor relationship adds a shared mailbox. Four years in, that employee holds the access footprint of three roles they no longer perform.

Multiply that by every tenured employee and the picture is clear enough without a statistic. Departing staff get disabled; staying staff keep everything they ever touched. The only reliable cleanup event in the employee lifecycle is also the least consequential one.

That accumulated reach determines the cost of your next incident. Credential compromise and business email compromise do not care about headcount. They care what one compromised identity can touch. The distance between a contained event and a disclosure-triggering one is often nothing more than whether the account the attacker landed on still had reach into something it stopped needing in 2022. Permission pruning is not hygiene. It is blast-radius management, and it is among the cheapest controls available to a mid-market business — which is precisely why it loses to work that arrives with a purchase order attached.

Flip the default from keep to revoke

Here is the change that makes the quarterly review worth the afternoon. In most organizations the review runs on an implicit default: access is retained unless someone objects. A list goes out, nobody has time to study it, nobody objects, everything stays. The exercise produces an artifact and changes nothing.

Invert that. Access is revoked unless a named person affirmatively justifies keeping it. The burden of proof moves from removal to retention.

Executives resist this because it sounds disruptive. In practice the disruption is small and self-correcting, for a reason worth understanding: access nobody will defend is almost always access nobody is using. When a revocation does break something, the break surfaces within a day or two as a help desk ticket and gets restored with a documented business reason attached. That ticket is not a failure of the process. It converts an undocumented standing permission into a justified one, on the record.

Two structural moves shrink how much there is to review at all. Privileged access granted just in time rather than held standing, so administrative rights exist for the duration of a task. Conditional access policies that gate sensitive resources on device and risk signals, so a valid credential alone is not sufficient. Neither replaces the review, because neither answers whether a given person should hold a given entitlement. Microsoft's identity platform includes tooling to run recurring reviews and route them to a named reviewer; whether your licensing tier includes that capability is worth confirming before anyone designs a manual process around its absence.

The signature belongs to the business, not to IT

The most common way a well-intentioned review fails is that IT runs it alone. An administrator can tell you with precision that a controller holds read-write access to a particular SharePoint site. No administrator can tell you whether she should. That judgment lives with whoever owns the data.

Route the review by data owner rather than by system. Finance attests to finance systems, HR to personnel records, the clinical or legal or operational lead to their own. IT security supplies the inventory, flags the anomalies, and executes the decisions; the business makes them. Then keep the artifact — a dated record of who reviewed what, what was revoked, and what was justified. Pull your own cyber insurance renewal questionnaire and read the access-control questions on it; they are easier to answer honestly when that record exists. Organizations carrying HIPAA compliance obligations or working toward CMMC are expected to demonstrate periodic review rather than assert it. A review that happened but was never documented is, for evidentiary purposes, a review that did not happen. That is an observation about how evidence works, not legal advice.

What four afternoons a year actually buy

This work is unglamorous. It generates no dashboard, closes no deal, and appears in no board deck as a win. What it buys is the difference between an incident a response team contains before lunch and one that becomes a notification event with counsel on the call.

The whole program fits on a single page: an inventory that includes non-human identities and connected applications, not just employees; a default that favors revocation; sign-off from the data owner rather than from IT; a dated record of what was decided and why. Four afternoons a year, and the second one is faster than the first.

An opinion, offered as such: when a breach goes badly, the question that surfaces afterward is rarely which product was missing. It is what one compromised account was still allowed to reach, and who had last been asked to defend that.

Pro Link Systems has worked with Los Angeles businesses on exactly this kind of unglamorous operational discipline since 1999, from Woodland Hills. If nobody outside IT has ever pruned your tenant's permissions, that is the place to start — managed IT services.

Ready to talk to a real IT engineer?

Pro Link Systems has been protecting and managing IT for Los Angeles businesses since 1999. Book a free 15-minute discovery call — no pressure, no obligation, no scripts.