SaaS Security and Access Reviews: Who Still Has Access?
How to run quarterly SaaS access reviews: what to check, who reviews, how to remove access, and how the same review cuts license cost.
By the MI Solutions SAM team8 min read2 exhibits
Every SaaS application holds some company data, and every user account is a way into it. An access review asks a simple question for each application: does everyone who has access still need it? It is a security control, and often a compliance requirement. It also happens to be one of the best ways to find licenses nobody needs.
The quarterly cycle
Exhibit 1
What to check
Flags for every app in scope
A typical first review finds more than expected, and most findings are also licenses:
Exhibit 2
Who reviews
The application owner reviews the user list, and managers confirm their team members' needs. Security defines which apps are in scope and keeps the evidence.
01Security
Defines the scope and the rules, keeps the evidence.
02App owner
Reviews the full user list and privileged roles.
03Managers
Confirm each team member's need.
04SAM
Releases licenses and reduces the count at renewal.
The cost side
Every removed account is a license you may not need at renewal. Coordinate access reviews with license reclamation so savings are captured.
How MI One helps
Frequently asked questions
How often should access be reviewed?
Quarterly for sensitive apps; at least annually for the rest.
Is an access review the same as license reclamation?
They overlap. Access reviews focus on security, reclamation on cost; doing them together saves effort.
Which apps should be in scope first?
Those holding sensitive data, those with privileged roles, and those with the highest license cost.
See where your software budget goes
Bring your five largest vendors to a 30-minute call. Our SAM experts will show you where the savings usually hide, and how fast MI One can surface them.