assess.one – AI-powered business operations platform

Workflow Template

User Access Review Workflow

Security team runs a periodic user access review: owner defines scope and submits users/entitlements, each user's manager or system owner certifies or flags access against least-privilege, flagged access triggers a revocation/adjustment task, and the review is closed with a recorded outcome. A due date is set on certifications to enable follow-up on outstanding reviews.

If your last access review turned into a spreadsheet nightmare with half the managers ignoring your emails, this workflow fixes that. It walks each manager or system owner through certifying their team's access against least-privilege, automatically flags anything that needs revoking or adjusting, tracks the fix through to done, and closes out the review with a clean, recorded outcome. Your security team gets a full audit trail without having to chase a single person.

Business Outcomes

  • Cuts manual follow-up on outstanding certifications by automating due date tracking
  • Creates a full audit trail of who certified what access and when
  • Reduces time-to-remediate flagged access by routing it straight to an action step
  • Gives security teams a clear, closed-out record for every review cycle
  • Removes reliance on spreadsheets and email chains for access certification

Workflow Steps

Steps

  1. 1
    Create Access Review Recordcreate record

    Registers the review submission as an access review record.

  2. 2
    Set Status: Openupdate record

    Marks the review as open on creation.

  3. 3
    Set Certification Due Dateset due date

    Sets a due date on the record so outstanding certifications can be followed up.

  4. 4
    Set Status: Certification In Progressupdate record

    Updates status as certification task is assigned.

  5. 5
    Certify User Accesscreate task

    Manager or system owner reviews the user's entitlements against least-privilege and certifies or flags for change.

  6. 6
    Persist Certification Outcomeupdate record

    Writes the certifier's outcome and notes to the record so they appear in views and reports.

  7. 7
    Route on Certification Outcome

    Branches based on whether access was certified or flagged for change.

    certification_outcome: "Certified"Record Certified Outcome
    certification_outcome: "Flagged for Change"Set Status: Remediation In Progress
    DefaultRecord Certified Outcome
  8. 8
    Set Status: Remediation In Progressupdate record

    Updates status as access has been flagged and a remediation action is being assigned.

  9. 9
    Assign Revocation/Adjustment Actioncreate task

    Assigns a task to the security team to revoke or adjust the flagged access.

  10. 10
    Record Remediation Outcomeupdate record

    Persists the remediation action and outcome summary to the record.

  11. 11
    Record Certified Outcomeupdate record

    Persists the certification outcome summary to the record.

  12. 12
    Close Review (Certified)update record

    Marks the review complete after certification with no remediation needed.

  13. 13
    Close Review (Remediated)update record

    Marks the review complete after remediation action has been applied.

Fields

  • Review Owner Email*
  • Review Scope (systems, department, time period)*
  • User Name*
  • User Entitlements / Access List*
  • System / Application Name*
  • Manager / System Owner Email (for reference)
  • +7 more fields

Forms

User Access Review Intake

6 fields

Data Views

All Access Reviews

user_name, system_name, certification_outcome, remediation_action +1 more

Flagged / Outstanding Certifications

user_name, system_name, certification_outcome, review_status

Dashboard Widgets

Access Review PipelineCertification OutcomesRemediation Actions Taken
user access reviewaccess recertificationaccess reviewidentity governancepermissions audit

Similar Workflows

Similar Categories

FAQs

Do I need IT to set this up before we can run our first access review?

No. You publish the template directly in assess.one and it's live in seconds — no installation, no dev work. Your security team can define the scope, add the users and entitlements, and start the review the same day.

Can my team customise who certifies access — manager vs. system owner?

Yes, the certification step is fully configurable. You can assign it to a direct manager, a system owner, or route it based on the entitlement type, and change this at any time without rebuilding the workflow.

Is this suitable for regular compliance-driven access reviews, like quarterly SOX or ISO audits?

Yes, it's built for exactly that. The workflow records certification outcomes, remediation actions, and closure status, giving you a timestamped record you can hand to auditors without extra reporting work.

What happens when a manager flags a user's access instead of certifying it?

The workflow automatically routes flagged access into a remediation path, sets the status to 'Remediation In Progress', and assigns a revocation or adjustment task. Nothing falls through the cracks because the outcome determines the next step automatically.

Who needs access to this workflow inside assess.one?

Typically the security team owns the review setup and closure, while individual managers or system owners only need access to their own certification tasks. You control these permissions inside assess.one, so people only see what's relevant to them.

Can I set different due dates for different review cycles?

Yes, the certification due date is set per review record, so you can run a quick monthly check for privileged accounts and a longer quarterly review for standard access, side by side.

What happens if a certification is left outstanding past the due date?

The due date field lets you build in follow-up reminders or escalation logic directly in assess.one's notification settings. You can adjust who gets notified and how often without touching the underlying workflow structure.

How is the review actually closed out?

The review closes in one of two ways: 'Closed (Certified)' if all access was confirmed as appropriate, or 'Closed (Remediated)' once flagged access has been revoked or adjusted and the outcome recorded. Both paths leave a clear, closed status with the full history attached.

How long does it take to get this workflow running for our team?

Publishing takes minutes — there's no implementation project. Once it's live, your security team can immediately create the first access review record and start assigning certifications.

Ready to use this workflow?

Create a free account and customise this workflow for your business.

User Access Review & Certification Workflow | assess.one