A governance control that turns 'we review who has access' from a policy statement into an auditable record. Each confirmation stores who ran the review, when, how many members there were, and a frozen snapshot of every member's name, email, role and status at that moment. A Review due badge appears when the last review is older than a year, or has never happened.
Also called: who has access · annual review · security audit · compliance evidence · last sign in
- 1Opening the panel loads the tenant's user list and the review history together.
- 2Each member row shows name, email, role, non-approved status, and last sign-in date.
- 3Confirm access reviewed posts the member snapshot; the history list shows the last several reviews with date, count and reviewer.
- 4The panel only tags itself for bug reports while expanded — a collapsed section is not a place you are.
The migration header states the purpose: the review table 'operationalizes the periodic access reviews are performed control and gives a real, auditable record rather than just a policy statement' — the security policy documents the control; this table and UI make it real. Each row is a frozen snapshot so the review is reproducible.
- Nobody could show evidence that access had ever been reviewed.
- Dormant accounts were invisible without checking sign-in dates one by one.
See it on your own jobs
Twenty minutes, your numbers, no slide deck. We’ll build one of your real buildings in front of you and send you the estimate link at the end — yours to keep either way.
or keep browsing features →