Most user access reviews can prove that a campaign happened. Far fewer can prove that it removed meaningful risk.
The problem usually is not reviewer discipline. It is the information reviewers receive.
I have spoken with security leaders who send managers a spreadsheet with hundreds of entitlements and ask them to approve or revoke each one. Nearly every row comes back approved.
It is easy to blame the manager. But approving everything is often the rational choice when the sheet does not explain whether the access is used, why it exists, who depends on it, or what could break if it is removed.
The cost of a mistaken removal is immediate and visible. The cost of an unnecessary approval is distant and abstract. So the campaign closes, compliance gets its evidence, and the risky access survives another quarter.
The review fails before the reviewer opens it
Most access reviews are presented as decisions but delivered as inventories.
A row might include a user, application, group, and entitlement name that made sense to the administrator who created it three years ago. That is not enough for a business owner to determine whether the access is still necessary.
The reviewer needs to know:
- Has the access been used recently?
- Does that activity fit the person’s current role?
- Why was the access granted?
- Who approved it?
- Was it supposed to be temporary?
- What workflow could break if it is removed?
That evidence rarely exists in one system, identity platforms contain part of it and the rest may live in tickets, Slack threads, HR records, application logs, or someone’s memory.
When the review platform cannot assemble that context, it transfers the investigation to the manager. Most managers do not have the time, tools, or incentive to reconstruct the history of every entitlement. The process rewards the answer that creates the least immediate disruption: approve.
Lifecycle gaps become review debt
Access reviews inherit every failure in the joiner, mover, and leaver process.
Employee offboarding may begin with a reliable HR event. A contractor’s departure may depend on someone remembering to open a ticket. Temporary access granted during an incident may have no expiration date. A service account may outlive the project that created it because nobody owns it anymore.
The quarterly review then becomes the cleanup process for identity decisions that should have been resolved months earlier.
That is too much work for a spreadsheet, and far too late for access that should already be gone.
Periodic reviews cannot govern AI agents
Periodic certification is already late for human access. For AI agents, the model breaks completely.
A human may make dozens of meaningful access decisions during a quarter. An agent can take thousands of actions across multiple connected systems before the next review begins.
Governance for agents therefore has to be continuous. The control needs to evaluate whether the agent’s current actions match its approved task, whether its delegated authority has expanded, and whether that access should still remain active.
Periodic evidence still matters for audit purposes. But the quarterly campaign cannot be the control itself.
Coverage is only as good as the denominator
Even a well-run review only covers the systems connected to it.
Coverage percentages are often presented as though they represent the organization. In practice, they may represent only the applications that were easy enough to integrate.
The missing systems are rarely low risk. They often include smaller SaaS applications, acquired systems, shared accounts, local application roles, contractor access, and older platforms with unclear ownership. These are also the places where access is most likely to survive after its original purpose ends.
Before asking what percentage of access was reviewed, ask what never entered the campaign:
- Which applications were excluded?
- Which identities were not covered?
- Which local roles and access paths remain invisible?
- Which accounts have no accountable owner?
A strong percentage against a weak denominator is not meaningful coverage.
A review should produce an explainable action
A useful access review should do more than ask whether access should remain.
It should present the evidence behind the recommendation, identify the accountable owner, explain the likely impact of removal, route uncertainty to the right person, and record what happened after the decision.
Where the underlying system supports it, the process should also verify that the approved change actually altered effective access. A revocation request is not the same as a completed revocation.
This changes the reviewer’s job. Instead of conducting a small investigation for every entitlement, the reviewer evaluates a recommendation with the relevant facts already assembled.
It also creates a better audit record. The organization can show not only that access was approved or revoked, but why the decision made sense and whether the change was completed.
How Offroad helps
Offroad’s AI agents can run full access review campaigns end to end: define the scope, gather context, generate recommendations, route decisions to the right owners, execute approved changes, verify effective access, and preserve the evidence behind every action.
The same agents work continuously between campaigns. They support least privilege by finding and removing unnecessary access, enforce zero trust by evaluating access against current identity and activity context, and help complete joiner, mover, and leaver processes before gaps become review debt.
The goal is not to complete the same checkbox faster. It is to make access reviews leave the environment safer than they found it.

.png)
