An Excel workbook for SOC 2, ISO 27001, PCI DSS, HIPAA, and NIST access reviews — covering human and non-human identities, with automatic risk flagging and a finished audit report at the end.
If your company is working toward SOC 2, ISO 27001, PCI DSS, HIPAA, or trying to pass a customer security questionnaire, you already know the one control every framework converges on: can you prove who has access to what, and that someone actually checked? Most small and mid-sized teams do this manually — tedious, error-prone, and usually the first thing an auditor picks apart.
It shows up, in some form, across nearly every major security and privacy framework a growing company runs into.
Trust Services Criteria CC6.1–CC6.3 require logical access controls and periodic review of who has access.
Requirement 7.2.4 requires reviewing user accounts and access every six months; 7.2.5/7.2.5.1 extends this to system and service accounts.
The Security Rule's administrative safeguards require access authorization and periodic evaluation (45 CFR §164.308).
Control AC-2(j) requires reviewing accounts for compliance with account management requirements at an organization-defined frequency.
Access review is a standard IT General Control tested as part of internal controls over financial reporting.
Requires managing access rights and periodic review of privileged access as part of the ICT risk management framework.
Article 32's "appropriate technical and organisational measures" are commonly evidenced through documented access control reviews.
API keys, service accounts, bots, OAuth tokens, and certificates are reviewed alongside employees, not as an afterthought.
6-state Risk Flag engineDormant accounts, never-used accounts, access not revoked after deactivation, privileged access, and non-human identities with no assigned owner.
Configurable thresholds, no formulas to touchAssign identities to reviewers, track who actually reviewed what, and catch mismatches between who was assigned and who reviewed automatically.
5-state Delegation CheckEvery Revoked decision auto-extracts into one clean list, tracking whether the removal was actually executed — not just decided.
Ticket-reference execution trackingFlags any review where the reviewer and the identity being reviewed are the same person — a real independence problem auditors look for.
Automatic, no setup requiredCompiles into a one-page, signable evidence document, ready to hand your auditor. No manual tallying.
Pulls live from Review SummaryFrom Okta, Google Workspace, Azure AD, AWS IAM, or any system that exports to CSV — users and service accounts alike.
A general mapping method plus worked examples for four major identity providers, included in the workbook.
Risk Flag, Review Status, and Delegation Check calculate automatically the moment data lands.
Assign rows to reviewers; each reviewer filters to just their own queue.
Certify, revoke, or modify each flagged identity. Review Summary and the Audit Report update themselves.
| Capability | Plain spreadsheet | Access Review Toolkit | Enterprise IGA platform |
|---|---|---|---|
| Automatic risk flagging | No | Yes | Yes |
| Non-human identity coverage | No | Yes | Yes |
| Delegation & attribution tracking | No | Yes | Yes |
| Segregation-of-duties conflict detection | No | No | Yes |
| Setup time | None | Minutes | Weeks |
| Typical annual cost | $0 | $99–$399 one-time | $10,000+ |
Every screenshot below is pulled from an actual finished review — 23 identities, human and non-human, fully flagged, delegated, decided, and reported. This is exactly what you're buying, not a staged demo.
A periodic check of who has access to what across an organization's systems, confirming that each person or automated identity still needs the access they have. It's a required or expected control under SOC 2, ISO 27001, PCI DSS, HIPAA, NIST 800-53, SOX, GDPR, and EU DORA.
Yes. It produces a dated, decided, attributable record of access review activity, matching the evidence auditors look for under SOC 2 Trust Services Criteria CC6.1–CC6.3, compiled into a one-page Audit Report ready to hand to an auditor.
Yes. Unlike most access review templates, which only track human user accounts, this toolkit treats API keys, service accounts, bots, OAuth tokens, and certificates as first-class identities, including a specific check for non-human identities with no assigned business owner.
No. All risk flagging, delegation tracking, and reporting is pre-built into the workbook. You paste in your identity export and fill in decisions; the formulas do the rest. A step-by-step illustrated guide is included.
The Single-Company Edition is licensed for one organization's own access reviews. The MSP / Consultant Edition is licensed for use across multiple client engagements, and adds a Client Tracker tab for managing review schedules across an entire client roster — Starter (up to 5 clients) or Growth (unlimited).
For a small or mid-sized organization doing access reviews manually today, it's a significant upgrade over a plain spreadsheet. It is not a replacement for a dedicated IGA platform at enterprise scale, and does not perform segregation-of-duties conflict detection across roles.
TekMicro Solutions builds practical, no-nonsense tools for teams doing access reviews and identity governance work manually today. The Access Review Toolkit was built by a compliance and identity governance practitioner with years of hands-on experience running exactly this control the hard way — by hand, in a spreadsheet, once a quarter — before building something better.