Access Reviews
Access reviews turn CIEM output into an attestation workflow. Every identity gets a state, an owner, and an outcome — so a review is a tracked decision rather than a spreadsheet emailed once a quarter and answered by nobody.
Review states
| State | Meaning |
|---|---|
| Pending | Awaiting a reviewer's decision |
| Needs remediation | Reviewed, and something must change |
| Reviewed | Decision recorded, no change needed |
| Deferred | Explicitly postponed, with the deferral recorded |
Deferred is a first-class state on purpose. A review process without one produces reviewers who mark things "reviewed" to clear the queue, which is worse than an honest backlog.
The finding stays attached
Each identity under review carries the CIEM finding that flagged it — the unused permissions, the escalation path, the stale credential. A reviewer who cannot see why an identity was flagged approves it, every time.
What reviews cover
Reviews run across the same identity population CIEM resolves: human users, roles, service accounts and machine identities, with their effective permissions and 90-day usage attached.
Auditor evidence
Because each review carries its state, its owner and its timestamp, the review history is the evidence an access-review control asks for — rather than a screenshot of a spreadsheet assembled the week before the audit.
Related: CIEM produces the findings; access reviews are how they get decided.