Eloope Logo

Access reviews

Periodically review who has access to what in your organization. Access reviews help you meet SOC 2, ISO 27001, and other compliance requirements by ensuring users only have the permissions they need.

What access reviews are

An access review is a structured process where a designated reviewer examines each user's roles and permissions. The reviewer confirms that access levels are correct, flags accounts that need changes, and revokes access that is no longer appropriate.

Eloope tracks the entire review process so you have a clear audit trail for compliance audits.

Note: Only administrators can create and manage access reviews.

Create an access review

  1. Go to Admin Settings in the left sidebar.
  2. Select Access Reviews.
  3. Click New Review.
  4. Enter a Review Name (e.g., "Q1 2026 Access Review").
  5. Assign a Reviewer: The person responsible for completing the review.
  6. Set a Deadline for when the review must be finished.
  7. Click Create.

The New Review form showing name, reviewer, and deadline fields

Complete a review

Once a review is created, the assigned reviewer receives a notification. To complete the review:

  1. Go to Admin Settings > Access Reviews.
  2. Open the review assigned to you.
  3. For each user listed, review their current roles and permissions.
  4. Mark each user with one of three decisions:
    • Confirmed: Access is correct and should remain unchanged.
    • Revoke: Access should be removed entirely.
    • Modify: Access needs to be adjusted (add a note describing the change).
  5. Click Submit Review when all users have been reviewed.

The access review screen showing a list of users with Confirmed, Revoke, and Modify options

Track review progress

While a review is in progress, administrators can monitor completion on the Access Reviews page. Each review shows:

  • The reviewer's name.
  • The deadline.
  • A progress bar showing percentage complete (e.g., 15 of 20 users reviewed).
  • The current status: In Progress, Completed, or Overdue.

Review history

All past access reviews are stored in the Review History tab. For each completed review, you can see:

  • The review name and date.
  • Who performed the review.
  • A summary of decisions (how many users were confirmed, revoked, or modified).
  • The full detail of each decision for audit purposes.

This history provides the documentation you need for compliance audits and internal governance reviews.

Warning: Overdue reviews are flagged on the admin dashboard. Complete reviews before their deadline to maintain compliance.

Up next

Learn Delegates and out of officein Eloope.


Did this article answer your question?