Access reviews
Regular access reviews, one account at a time
Paste the account list of a system, let the reviewer decide keep, change or remove for each account, and complete the review as proof. The reviewer only sees the review given to them.

How it works
Start a review
Name the system, link the asset, choose the reviewer and a due date.
Decide per account
Paste the exported accounts or add your members, then choose keep, change or remove with a note.
Complete it
When every account is decided, add a conclusion. The decisions are locked as your record.
What changes for you
Reviewers without broad access
A reviewer opens only their own review, even as a plain member.
Fast for long lists
Up to 500 accounts per review, with keep all undecided for the obvious ones.
Private by default
Account names never go into the audit log, only counts and decisions.
What it covers
- NIS2 21(2)(i)
- ISO 27001 A.5.18
Works together with
Questions
Does CloudSignLab change the accounts?
No. Carry out the changes and removals in the system itself; CloudSignLab keeps the record of what was decided.
What if a review is late?
Open reviews appear in the reviewer's Tasks and get a reminder once they are overdue.
Run your first access review
Start with the system that holds your most sensitive data.
