Audit-Ready Identity Governance

A user access review template that actually holds up to an auditor.

An Excel workbook for SOC 2, ISO 27001, PCI DSS, HIPAA, and NIST access reviews — covering human and non-human identities, with automatic risk flagging and a finished audit report at the end.

Review Summary ✓ Live Workbook
Total identities in scope1,000 supported
Pre-built formulas9,075
Risk Flag states6
Conditional format rules16
Human + non-human coverageYes
Review completion100% possible

Most access reviews are done by hand, once a quarter, in a spreadsheet with no formulas.

If your company is working toward SOC 2, ISO 27001, PCI DSS, HIPAA, or trying to pass a customer security questionnaire, you already know the one control every framework converges on: can you prove who has access to what, and that someone actually checked? Most small and mid-sized teams do this manually — tedious, error-prone, and usually the first thing an auditor picks apart.


Access review isn't a one-framework requirement.

It shows up, in some form, across nearly every major security and privacy framework a growing company runs into.

SOC 2 ISO 27001 PCI DSS 4.0 HIPAA NIST 800-53 SOX (ITGC) EU DORA GDPR
SOC 2

Trust Services Criteria CC6.1–CC6.3 require logical access controls and periodic review of who has access.

PCI DSS 4.0

Requirement 7.2.4 requires reviewing user accounts and access every six months; 7.2.5/7.2.5.1 extends this to system and service accounts.

HIPAA

The Security Rule's administrative safeguards require access authorization and periodic evaluation (45 CFR §164.308).

NIST 800-53

Control AC-2(j) requires reviewing accounts for compliance with account management requirements at an organization-defined frequency.

SOX (ITGC)

Access review is a standard IT General Control tested as part of internal controls over financial reporting.

EU DORA

Requires managing access rights and periodic review of privileged access as part of the ICT risk management framework.

GDPR

Article 32's "appropriate technical and organisational measures" are commonly evidenced through documented access control reviews.


Built for what most templates skip entirely.

Human and non-human identities

API keys, service accounts, bots, OAuth tokens, and certificates are reviewed alongside employees, not as an afterthought.

6-state Risk Flag engine

Automatic risk flagging

Dormant accounts, never-used accounts, access not revoked after deactivation, privileged access, and non-human identities with no assigned owner.

Configurable thresholds, no formulas to touch

Delegation and attribution

Assign identities to reviewers, track who actually reviewed what, and catch mismatches between who was assigned and who reviewed automatically.

5-state Delegation Check

Removals Log

Every Revoked decision auto-extracts into one clean list, tracking whether the removal was actually executed — not just decided.

Ticket-reference execution tracking

Self-review detection

Flags any review where the reviewer and the identity being reviewed are the same person — a real independence problem auditors look for.

Automatic, no setup required

A finished Audit Report

Compiles into a one-page, signable evidence document, ready to hand your auditor. No manual tallying.

Pulls live from Review Summary

Export, map once, paste, decide, done.

Export your identity list

From Okta, Google Workspace, Azure AD, AWS IAM, or any system that exports to CSV — users and service accounts alike.

Map it once

A general mapping method plus worked examples for four major identity providers, included in the workbook.

Paste and let it flag

Risk Flag, Review Status, and Delegation Check calculate automatically the moment data lands.

Delegate if needed

Assign rows to reviewers; each reviewer filters to just their own queue.

Decide and hand over the report

Certify, revoke, or modify each flagged identity. Review Summary and the Audit Report update themselves.


More than a blank spreadsheet. Less than an enterprise platform.

CapabilityPlain spreadsheetAccess Review ToolkitEnterprise IGA platform
Automatic risk flaggingNoYesYes
Non-human identity coverageNoYesYes
Delegation & attribution trackingNoYesYes
Segregation-of-duties conflict detectionNoNoYes
Setup timeNoneMinutesWeeks
Typical annual cost$0$99–$399 one-time$10,000+

A real completed audit, not a mockup.

Every screenshot below is pulled from an actual finished review — 23 identities, human and non-human, fully flagged, delegated, decided, and reported. This is exactly what you're buying, not a staged demo.

Access Data tab from a completed audit, showing automatic risk flags across 23 human and non-human identities
Access Data — every identity flagged, delegated, and resolved automatically
Removals Log tab auto-extracting every revoked identity with ticket references
Removals Log — auto-generated, one item completed and one still pending execution
Role Matrix reference tab showing expected access by department and role
Role Matrix — expected access by role, for spotting outliers by eye
Review Summary tab showing live rollup counts and percentages
Review Summary — live counts and percentages, zero manual tallying
Finished one-page Audit Report ready to hand to an auditor
Audit Report — the finished, signable page you hand your auditor

Pick based on who you're reviewing access for.

Single-Company

For your own organization's access reviews
$99
  • Full Risk Flag & Delegation engine
  • Role Matrix & Removals Log
  • Self-review detection
  • Illustrated step-by-step guide
Buy now

MSP Growth

Unlimited client engagements
$399
  • Everything in MSP Starter
  • No client cap
  • Best per-client value at scale
Buy now

Common questions

What is a user access review?

A periodic check of who has access to what across an organization's systems, confirming that each person or automated identity still needs the access they have. It's a required or expected control under SOC 2, ISO 27001, PCI DSS, HIPAA, NIST 800-53, SOX, GDPR, and EU DORA.

Does this template work for SOC 2 audits?

Yes. It produces a dated, decided, attributable record of access review activity, matching the evidence auditors look for under SOC 2 Trust Services Criteria CC6.1–CC6.3, compiled into a one-page Audit Report ready to hand to an auditor.

Does it cover non-human identities like API keys and service accounts?

Yes. Unlike most access review templates, which only track human user accounts, this toolkit treats API keys, service accounts, bots, OAuth tokens, and certificates as first-class identities, including a specific check for non-human identities with no assigned business owner.

Do I need to know Excel formulas to use it?

No. All risk flagging, delegation tracking, and reporting is pre-built into the workbook. You paste in your identity export and fill in decisions; the formulas do the rest. A step-by-step illustrated guide is included.

What's the difference between the Single-Company and MSP editions?

The Single-Company Edition is licensed for one organization's own access reviews. The MSP / Consultant Edition is licensed for use across multiple client engagements, and adds a Client Tracker tab for managing review schedules across an entire client roster — Starter (up to 5 clients) or Growth (unlimited).

Can I use this instead of a dedicated identity governance platform?

For a small or mid-sized organization doing access reviews manually today, it's a significant upgrade over a plain spreadsheet. It is not a replacement for a dedicated IGA platform at enterprise scale, and does not perform segregation-of-duties conflict detection across roles.


Built by someone who's done this by hand.

TekMicro Solutions builds practical, no-nonsense tools for teams doing access reviews and identity governance work manually today. The Access Review Toolkit was built by a compliance and identity governance practitioner with years of hands-on experience running exactly this control the hard way — by hand, in a spreadsheet, once a quarter — before building something better.