Home/Blog/How to Complete a Quarterly Access Review in Ten Business Days
Operations

How to Complete a Quarterly Access Review in Ten Business Days

Every access review program has a moment where the campaign that was supposed to close in two weeks is still open six weeks later. Reviewer momentum is gone, the population no longer matches the live state, and the evidence bundle is a moving target. Compressing the cadence is the single highest-leverage move for a program that keeps slipping.

Ten business days is not aggressive. It is the natural length of a campaign that has been scoped and instrumented correctly. Here is the day-by-day.

Why should a quarterly access review close in ten days?

Three reasons, in order of load-bearing weight.

  • Reviewer attention decays fast. Manager engagement with a campaign drops 40 to 60% between week one and week three. A ten-day campaign captures the high-engagement window and closes before decay sets in.
  • The population drifts. Joiners, movers, and terminations happen weekly. A campaign that spans six weeks is reviewing an entitlement snapshot that no longer exists by the end.
  • Audit evidence is stronger when tight. A campaign that opens and closes in the same reporting window produces cleaner evidence. Auditors do not love campaigns that straddle month-end or quarter-end.

If your campaigns run six weeks, the underlying reason is almost never that reviewers are slow. It is that the campaign is scoped or routed wrong.

What has to be true before day zero?

Three pre-campaign artifacts. Do not launch without them.

  • Entitlement population, frozen. Snapshot every entitlement in scope, per user, per system. Timestamp it. This is your evidence starting point.
  • Reviewer routing map. Every entitlement mapped to a named reviewer (usually the direct manager) with a fallback (usually the manager's manager or the application owner).
  • Plain-language descriptions. Every unique entitlement translated once. github:org:admin becomes "Full admin of the GitHub organization". This work is done before campaign launch, not during.

If any of these three is missing on day zero, delay the launch. Launching without them turns the campaign into a support ticket queue for the IAM team.

What does day-by-day execution look like?

Ten business days. Predictable checkpoints.

Day Action Owner
0 Campaign launches, reviewer Slack + email Campaign owner
1 Reviewer dashboard active, first decisions land Reviewers
3 First automated nudge to non-starters (0% complete) System
6 Manager escalation to any reviewer under 50% Campaign owner
7 Second nudge to reviewers still open System
8 Decision cutoff. Anything unresolved routes to fallback Campaign owner
9 Revocation execution runs, evidence attaches System + IT
10 Campaign closes, evidence bundle exported Campaign owner

The checkpoints matter more than the days themselves. Miss a checkpoint and the campaign starts drifting.

What triggers a reviewer escalation?

Three explicit triggers. Do not improvise.

  • Non-starter at day 3. Zero decisions logged. Automated nudge to reviewer directly, no manager loop yet.
  • Under 50% at day 6. Manager of the reviewer gets a copy of the campaign status. This is the highest-leverage nudge in the cadence.
  • Under 100% at day 8. Remaining items transfer to fallback reviewer (usually the reviewer's manager or the application owner). Original reviewer gets a note; no penalty, just a handoff.

The manager-of-reviewer escalation on day 6 is the checkpoint most programs skip. It is also the one that keeps campaigns on schedule.

How do you run the revocation execution phase?

Days 8 to 10 are pure execution. Two rules.

  • Rule 1. Every "revoke" decision executes through the source system's API within 5 business days. For apps without a write API, IT gets a task with a due date; the task attaches an executed-state screenshot when it closes.
  • Rule 2. The evidence bundle is not exported until execution rate is above 95%. If execution is at 70% on day 10, the campaign is not closed; it is late.

The most common failure mode is treating the reviewer's click as the end of the process. The revocation execution is the process. The click is the trigger.

What goes into the evidence bundle at close?

Six artifacts, exported as one package.

  1. Entitlement population at day 0. Frozen CSV.
  2. Decision log. Every entitlement, every reviewer, every timestamp, every decision.
  3. Revocation execution proofs. API response or task-close artifact per revoke decision.
  4. Escalation log. Every day-6 and day-8 escalation, resolved or transferred.
  5. Fallback log. Every decision made by a fallback reviewer rather than the primary.
  6. Signed campaign attestation. One page, signed by the CISO or head of IT.

Package these together. If your auditor has to email you back for artifact three or six, your bundle is not audit-ready.

What are the failure modes of a ten-day cadence?

Three, all preventable.

  • Scope creep during the campaign. Adding new systems mid-campaign is the single most common ten-day-to-forty-day escalator. New systems get their own campaign.
  • Comment fields on every decision. Requiring a comment on every approval or revoke triples campaign time and does not improve decision quality. Reserve comments for exceptions and escalations only.
  • The security team makes decisions on behalf of unresponsive reviewers. This corrupts the evidence and undermines the control. Escalate or fail-over to a named fallback reviewer; never substitute the security team.

If you see any of these creeping in, name them explicitly and cut them. Ten days does not survive scope creep.

What benchmarks tell you the cadence is working?

Six numbers, tracked cycle over cycle.

  • Campaign duration. Target: 10 business days from launch to bundle export.
  • Reviewer completion rate at day 8. Target: 95%+.
  • Escalation rate. Target: 10 to 20% of reviewers hit day-6 escalation. Below 10%, you are probably too slack. Above 25%, reviewer routing is wrong.
  • Revocation execution rate at day 10. Target: 95%+.
  • Fallback-reviewer decision rate. Target: under 5% of total decisions.
  • Post-campaign audit findings. Target: zero related to timeliness or completeness.

Hit those six and the cadence is real. Miss on any of them for two cycles running and something in the process needs to change.

The mistake to avoid

The default reflex when a campaign is late is to extend it. Extending campaigns teaches reviewers the deadline is fake. Instead, enforce the day-8 cutoff, fail unresolved items over to fallback reviewers, and publish the campaign duration alongside completion rate. Reviewers respond to visible cadence, not to reminder emails. The ten-day campaign works because everyone in the loop knows the calendar is real.

access reviewquarterly reviewiam operationscampaign cadencegrc

Frequently asked questions

Ten days feels aggressive. Are auditors okay with that?

Auditors care about completeness and execution, not campaign duration. A ten-day campaign that produces a complete population, real decisions, and executed revocations is stronger evidence than a six-week campaign with the same output. Short campaigns actually help audit posture because the entitlement snapshot at campaign start matches the executed state at campaign close.

What if reviewers are on vacation or unresponsive?

Escalate to their manager on day 6 if the reviewer is under 50% complete. If still unresponsive by day 8, transfer the pending items to the reviewer's manager or to the application owner as a fallback. Every campaign will have 2 to 5% orphaned decisions; you need a documented escalation path so those get closed rather than dropped.

Can we run monthly instead of quarterly?

Yes, if you have the tooling to keep the population fresh and the reviewer bandwidth to sustain it. Monthly is common for privileged access at regulated companies. Standard SaaS access reviewed monthly is usually diminishing returns; quarterly for standard, monthly for privileged, and event-driven for role changes is the pattern most mature programs run.

How do we handle joiner and mover events during a campaign?

Freeze the campaign scope at day 0. New joiners and role changes after day 0 are handled by your event-driven provisioning process, not by the current campaign. Trying to update campaign scope mid-cycle is the single most common reason ten-day campaigns turn into forty-day campaigns.

What is the campaign owner's actual job?

Route escalations, unblock reviewers, and enforce the decision cutoff. Not to make access decisions. The most common mistake is a security team that treats the campaign as their review to complete; it is the managers' review, and the security team's job is to run the process, not to judge access on behalf of managers who did not respond.

Close access reviews in days, not quarters

Orvaron pulls entitlements from every system, routes reviews to the right manager, and executes revocations in the source app so evidence builds itself.

Request early access