I’ve been thinking about access governance and one question keeps coming up:
How much audit information do teams actually need?
For example, should an access audit record only capture major events like:
Access requested
Access approved/rejected
Access provisioned
Access revoked
Or should it go deeper and capture:
Who requested it?
Who approved it?
What access was granted or removed?
Which application, group or role changed?
Why was it requested?
When did it happen?
Was the access temporary?
When was it last reviewed?
What happened during the review?
But there’s another part of auditing that I find even more interesting:
What about access that was granted but is never actually used?
Someone may have access to an application or group for 6 months, but perhaps they haven't used it once.
Should that automatically trigger a review?
For example:
User has Salesforce access → hasn't used Salesforce for 90 days → should the system flag it for review?
Or is usage alone not enough to make that decision? Maybe the access is intentionally kept for occasional or emergency use.
So I'm curious how others handle this:
Do you track unused/dormant access as part of your access governance strategy?
And if you do, what would you consider a reasonable threshold: 30, 60, 90, 180 days, or something else?
Also, what should happen after it's flagged, notify the manager/lead, start an access review, or automatically revoke it?
Would be interested to hear how teams are approaching this in JSM, Okta, or other IAM setups.