MI Solutions
Insights/SaaS management
SaaS management

SaaS Security and Access Reviews: Who Still Has Access?

How to run quarterly SaaS access reviews: what to check, who reviews, how to remove access, and how the same review cuts license cost.

By the MI Solutions SAM team8 min read2 exhibits

Every SaaS application holds some company data, and every user account is a way into it. An access review asks a simple question for each application: does everyone who has access still need it? It is a security control, and often a compliance requirement. It also happens to be one of the best ways to find licenses nobody needs.

The quarterly cycle

Exhibit 1
A quarterly access review cuts risk and cost togetherOne review cycle, in weeks01234WeeksExtractUsers, roles andlast activity perappFlagLeavers, inactive,privileged rolesReviewOwners confirm orrevoke each userRemoveRevoke access andrelease licensesRecordEvidence kept forauditors

What to check

Flags for every app in scope

A typical first review finds more than expected, and most findings are also licenses:

Exhibit 2
Most access-review findings are also license savingsAccounts flagged in a first quarterly review across 12 apps, illustrative0100200300400500Inactive for 90+ days412Leavers with activeaccounts137External users past enddate64Excess admin rights38Shared or genericaccounts21Illustrative. Inactive and leaver accounts usually also hold paid licenses; admin and shared-account findingsare mainly security fixes.

Who reviews

The application owner reviews the user list, and managers confirm their team members' needs. Security defines which apps are in scope and keeps the evidence.

01Security

Defines the scope and the rules, keeps the evidence.

02App owner

Reviews the full user list and privileged roles.

03Managers

Confirm each team member's need.

04SAM

Releases licenses and reduces the count at renewal.

The cost side

Every removed account is a license you may not need at renewal. Coordinate access reviews with license reclamation so savings are captured.

How MI One helps

Frequently asked questions

How often should access be reviewed?

Quarterly for sensitive apps; at least annually for the rest.

Is an access review the same as license reclamation?

They overlap. Access reviews focus on security, reclamation on cost; doing them together saves effort.

Which apps should be in scope first?

Those holding sensitive data, those with privileged roles, and those with the highest license cost.

See where your software budget goes

Bring your five largest vendors to a 30-minute call. Our SAM experts will show you where the savings usually hide, and how fast MI One can surface them.