Skip to content
Glossary
Audit

User Access Review (UAR)

A periodic review confirming each person's system access is still appropriate for their role.

A User Access Review (UAR), also called an access recertification, is a periodic check that the access each user holds across systems is still justified by their current role and responsibilities. Reviewers — typically managers or system owners — confirm, revoke, or adjust entitlements, and the outcomes are recorded as evidence.

UARs counter “access creep”, the gradual accumulation of permissions as people change roles, join projects, or use temporary access that never gets removed. Leftover access is a major security exposure and a frequent audit finding. SOC 2, ISO 27001, and many regulatory regimes expect access to be reviewed on a regular cadence, often quarterly for sensitive systems.

The challenge is turning a sprawl of accounts and entitlements into a clean, reviewable picture and then capturing reviewer decisions in a way that satisfies an auditor — work that is painful and error-prone when done by spreadsheet.

Comply automates this — see the access reviews page.

See your compliance prove itself

Start free in minutes, or get a guided demo. No credit card, no per-seat surprises.

Free tier: 1 framework · 10 workers · 2 connectors. Upgrade only when you grow.