I’ve been thinking about access governance and one question keeps coming up:
How much audit information do teams actually need?
For example, should an access audit record only capture major events like:
Access requested
Access approved/rejected
Access provisioned
Access revoked
Or should it go deeper and capture:
Who requested it?
Who approved it?
What access was granted or removed?
Which application, group or role changed?
Why was it requested?
When did it happen?
Was the access temporary?
When was it last reviewed?
What happened during the review?
But there’s another part of auditing that I find even more interesting:
What about access that was granted but is never actually used?
Someone may have access to an application or group for 6 months, but perhaps they haven't used it once.
Should that automatically trigger a review?
For example:
User has Salesforce access → hasn't used Salesforce for 90 days → should the system flag it for review?
Or is usage alone not enough to make that decision? Maybe the access is intentionally kept for occasional or emergency use.
So I'm curious how others handle this:
Do you track unused/dormant access as part of your access governance strategy?
And if you do, what would you consider a reasonable threshold: 30, 60, 90, 180 days, or something else?
Also, what should happen after it's flagged, notify the manager/lead, start an access review, or automatically revoke it?
Would be interested to hear how teams are approaching this in JSM, Okta, or other IAM setups.
Thank you for the interesting question.
About dormant account, In my opinion the policy should be:
- Setting a specific group for those users that don't use the tools but are required to have access (supervisors, someone like this ....)
- Set an automatic/manual deactivation after 6 month for standard users
Hope it helps
Hi @Matteo Vecchiato
Have you implemented this yourself or seen anyone implement it? If so, could you please share how it was achieved and what you consider the best approach? That would be really helpful.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.