Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

How much auditing is actually needed for access management?

James Anderson
August 24, 2026

I’ve been thinking about access governance and one question keeps coming up:

How much audit information do teams actually need?

For example, should an access audit record only capture major events like:

  • Access requested

  • Access approved/rejected

  • Access provisioned

  • Access revoked

Or should it go deeper and capture:

  • Who requested it?

  • Who approved it?

  • What access was granted or removed?

  • Which application, group or role changed?

  • Why was it requested?

  • When did it happen?

  • Was the access temporary?

  • When was it last reviewed?

  • What happened during the review?

But there’s another part of auditing that I find even more interesting:

What about access that was granted but is never actually used?

Someone may have access to an application or group for 6 months, but perhaps they haven't used it once.

Should that automatically trigger a review?

For example:

User has Salesforce access → hasn't used Salesforce for 90 days → should the system flag it for review?

Or is usage alone not enough to make that decision? Maybe the access is intentionally kept for occasional or emergency use.

So I'm curious how others handle this:

Do you track unused/dormant access as part of your access governance strategy?

And if you do, what would you consider a reasonable threshold: 30, 60, 90, 180 days, or something else?

Also, what should happen after it's flagged, notify the manager/lead, start an access review, or automatically revoke it?

Would be interested to hear how teams are approaching this in JSM, Okta, or other IAM setups.

1 answer

0 votes
Matteo Vecchiato
Community Champion
August 25, 2026

Hi @James Anderson 

Thank you for the interesting question.

About dormant account, In my opinion the policy should be:

- Setting a specific group for those users that don't use the tools but are required to have access (supervisors, someone like this ....)

- Set an automatic/manual deactivation after 6 month for standard users

Hope it helps

James Anderson
August 25, 2026

Hi @Matteo Vecchiato 

Have you implemented this yourself or seen anyone implement it? If so, could you please share how it was achieved and what you consider the best approach? That would be really helpful.

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
FREE
PERMISSIONS LEVEL
Product Admin Site Admin
TAGS
AUG Leaders

Atlassian Community Events