Glossary
Access review
Periodically rechecking who still needs access to what and removing the rest, which auditors ask about and organisations reliably postpone.
In plain terms
Somebody goes through the list of who can reach what, asks whether each person still needs it, and takes away what is no longer needed. It sounds like housekeeping and it is the only mechanism that catches the person who moved to a different team two years ago and kept everything they had.
Why it matters
Because access accumulates in one direction. Being granted something is a request somebody makes and somebody approves; losing it requires an absence to be noticed, which nothing prompts. Over a few years that asymmetry produces an estate where a great many people can reach a great many things nobody would grant them today, without any individual decision having been wrong.
How it works
The asymmetry is the whole mechanism and it is worth naming rather than treating as carelessness. Additions have an advocate and removals have nobody, so the drift is structural. That also means the remedy has to be scheduled rather than intended, because an activity with no natural trigger does not happen on good intentions.
Internal moves cause more of it than departures do. A leaver at least prompts somebody to act, whereas a person moving between teams keeps everything they had and gains what the new role needs, and nobody is prompted at all. The accumulated result is the person who can reach three departments' material entirely by accident of career.
Narrow beats thorough, because a review nobody completes achieves nothing. Asking managers to confirm a long list produces rubber-stamping; asking about the handful of tools where the material actually matters produces genuine answers. The version that gets done is worth more than the version that is comprehensive on paper.
AI tools are usually missing from the list, which is the specific gap worth closing. Assistants, search deployments and automation platforms are frequently adopted outside whatever process produced the inventory, so they escape the review that covers older systems. That is also where a search tool in particular can reach material from everywhere at once.
Two ways access is gained and one way it is lost
Seen in the wild
Checking who still holds assistant access after a reorganisation, including people who moved teams rather than left.
ChatGPTRechecking which departments a search deployment lets people reach, since it can surface material from across systems.
GleanReviewing who can change or connect automations, given they hold credentials for everything else you run.
Make
Common misconceptions
People assume
Our leaver process handles this.
In fact
It handles departures, which are the case with a natural prompt. Internal moves are the larger source and have no prompt at all, since somebody changing teams keeps everything they had and gains more. Those people are still present and nobody has any reason to look at their access.
People assume
A thorough review is better than a narrow one.
In fact
Only if it happens. A long list sent to busy managers produces confirmations rather than decisions, which records that a review occurred while changing nothing. A short list covering the tools where material actually matters produces real removals, and it is the version that gets completed.
Telling them apart
Access review vs Single sign on
Access review
Catching everybody who stayed and no longer needs what they have.
Closing access automatically when somebody leaves.
Central sign-in solves departures. Only a review solves the person who moved teams and kept everything.
Questions
- Why does access accumulate?
- Because granting has an advocate and removing has nobody. A request is made and approved; a removal requires somebody to notice an absence, which nothing prompts. That asymmetry is structural rather than careless, and it is why the remedy has to be a scheduled activity rather than an intention.
- What makes a review actually happen?
- Keeping it narrow. A long list sent to busy managers produces rubber-stamping and records that a review occurred while removing nothing. A short list covering the tools where the material genuinely matters produces real decisions, and it is the version that gets finished.
- Which AI tools should be on the list?
- The ones that reach material rather than the ones that cost most. Search deployments first, since they can surface content from across systems, then automation platforms holding credentials for everything else, then assistants. Those are frequently absent because they were adopted outside whatever produced the inventory.
Key takeaways
- Granting has an advocate and removing has nobody; the drift is structural.
- Internal moves cause more accumulation than departures do.
- A narrow review that happens beats a thorough one that gets rubber-stamped.
- AI tools are usually missing from the list, and search tools reach the most.
Last checked July 2026