Opening Scene
Every quarter, before the club’s next big event, the manager sits down with the current guest list and goes through it name by name: still a regular, moved away last spring, worked here but left the company in March. Nobody deliberately let those outdated entries stay on the list — they simply never got taken off, because nobody ever sat down and asked, deliberately, whether each name still belonged.
In Plain English
Access reviews and recertification are the scheduled, deliberate process of re-verifying that every existing grant of access — every role, every permission, every standing credential — is still justified. It’s a check that runs on a regular cadence, not a one-time setup step, precisely because access naturally accumulates and goes stale as people change roles, finish projects, or leave altogether, and nothing about a permissions system automatically notices that on its own.
The Old Way
Before access reviews were a routine, scheduled discipline:
- Access was typically reviewed only reactively, after an incident or an audit finding forced the question, rather than on a regular preventive schedule.
- Managers were often asked to approve long lists of permissions for their team with little real context on what each one actually meant or whether it was still needed.
- Access granted for a specific project frequently outlived the project itself by months or years, since nothing prompted anyone to revisit it.
Sitting down with the list before every event, deliberately and on a schedule, is exactly the practice that replaces that slow, silent accumulation of stale access.
What’s Changing (and Why AI Is the Reason)
- Organizations increasingly run access reviews as a regular, automated-workflow process rather than an occasional, manually organized scramble.
- This connects directly to the least privilege principle covered in Article 4, since recertification is the mechanism that actually enforces least privilege over time, rather than just at the moment access was first granted.
- The growing population of AI agents, each holding its own credentials, has made recertification considerably more complex, since reviewing “does this agent still need this access” requires understanding what the agent’s task actually is, not just recognizing a familiar employee’s name on a list.
The Metaphor, Fully Extended
| The Velvet Rope | Access Control Concept |
|---|---|
| Going through the guest list name by name before the next event | Reviewing every access grant on a scheduled cadence |
| A name that quietly never got removed after someone left | Access that quietly outlives the role or project that justified it |
| The manager actually checking each name’s current status | A reviewer actively verifying, not just rubber-stamping, each grant |
| A refreshed, accurate list heading into the next big night | A recertified, accurate access record heading into the next period |
For Beginners: What to Actually Do
- Respond promptly and thoughtfully when asked to confirm or review your own access, rather than treating it as a routine box to check.
- If you notice you still have access to something from a past role or project, proactively flag it for removal.
- Understand that having access revoked during a review isn’t a judgment on you personally; it’s the system working as intended.
For Practitioners and Leaders: The Deeper Layer
- Run access reviews on a regular, defined cadence, with clear ownership for who reviews what.
- Give reviewers genuine context on what each permission means, rather than asking them to approve a wall of unexplained entries.
- Extend recertification explicitly to AI agent credentials, reviewing whether each agent’s access still matches its current, actual task.
Quick Recap
- Access reviews and recertification are the scheduled process of re-verifying that existing access is still justified.
- Without them, access naturally accumulates and goes stale as roles and projects change.
- Reactive, incident-driven reviews are being replaced by regular, proactive ones.
- AI agent credentials increasingly need their own recertification process, reviewed against their actual current task.
Where This Fits in the Series
Article 10 covered the record of who accessed what; Article 11 covered the discipline of periodically rechecking whether that access still belongs. Article 12 takes the review process a step further, asking whether trust should ever really be “standing” at all, or checked freshly at every single door.
Subscribe to the Newsletter
Get the latest DataParables articles delivered straight to your inbox.