Skip to main content
The traditional access review is a spreadsheet exported on Monday, chased for three weeks, and signed off against data that stopped being true on Tuesday. If access grants already live in Ravenna as entitlements, the review can run against the live record instead.
Prerequisites: access provisioning set up, so entitlements exist. Reviews of access granted outside Ravenna are covered in step 6.

What good looks like

1

Reduce the review before you run it

The cheapest access review is the one with less to review. Two changes shrink it more than any process improvement:
  • Default to time-bound access. Access that expires does not need reviewing. Set your Standard and Elevated policies to Requester picks a duration and offer 30d and 90d.
  • Tier by risk. Privileged access reviewed quarterly and standard access reviewed annually is a defensible position. Reviewing everything quarterly means nothing gets read.
2

Review by application owner, not by employee

Reviewing per employee produces a manager staring at a list of thirty tools they do not understand. Reviewing per application produces an owner looking at a list of people they know, for a system they know.Each application in the catalog has an owner field. That field is your review assignment list.
3

Make each review a ticket with a task per decision

One ticket per application, assigned to its owner, with a due date. Use a task template so the review has visible structure:
  1. Review the active entitlements on the Entitlements tab
  2. Flag any grant that is no longer needed
  3. Revoke the flagged grants
  4. Confirm every remaining grant has a named business reason
  5. Record the review decision as a comment
The ticket is the evidence. It carries who reviewed, what they decided, when, and the discussion, without anyone assembling a pack afterwards.
Learn more in task templates
4

Act in place, and watch for failures

The Entitlements tab on an application shows every grant and its status. Reviewers can revoke or extend from there, so a decision and its execution are the same action.Two statuses deserve attention during a review:
  • Failed Revocation means the access is still live. This is the one that turns a clean review into an audit finding, and it is silent unless someone looks.
  • Skipped Revocation usually means another active grant still requires the access. That is correct behavior, not an error, but confirm the other grant is one you intended.
Learn more about entitlements
5

Automate the reminders and the failure alerts

Two workflows, and only two:
  • Kick off the review. On a schedule, create the review ticket per application and assign the owner. Reminder policies handle the chasing without you building it.
  • Alert on failed provisioning changes. Use the Entitlement Status Changed trigger to post to the Security triage channel whenever an entitlement lands on Failed Revocation. Do not wait for the next review to find these.
6

Handle the access that is not in Ravenna

Some access will not be there: tools provisioned before you started, or systems with no identity provider connection. Do not pretend otherwise in the review.Two workable approaches:
  • Add the application with Manual provisioning. Grants get recorded as entitlements and confirmed by an authorized provisioner, so they appear in the review even though the grant itself happens in the target system.
  • Pull the data with Foundry. A Foundry action against the tool’s API can list current users, which a workflow can attach to the review ticket. Worth building only for the systems an auditor asks about.
7

Assemble the evidence from what already exists

You need three things, and all three are already recorded:The audit log is organization admin only and exportable, which is usually what an auditor actually wants. Vanta covers the adjacent question of authentication method and MFA coverage per user.

Where teams get this wrong

Tier it, or reviewers stop reading.
Managers cannot assess thirty tools. Owners can assess one.
The moment you export, the review is against stale data and the revocations become someone else’s ticket.
This is the specific status that produces audit findings.
If access is still granted by DM, fix that first. A review process on top of shadow provisioning reviews nothing.

Next

Employee offboarding

The other place revocation has to be reliable.

Access provisioning

Where entitlements come from.
Last modified on September 17, 2026