UprootSecurity
Book a demo
Notion templateSOC 2 · CC6.3No email required

Quarterly access review

The control auditors love to fail you on. Work through every grant, decide keep, modify, or revoke, capture who signed off, and export a clean record to CSV or Markdown — drop it straight into Notion as your evidence for the quarter.

Security / Access reviews / Q2 2026
🔐

Quarterly access review — Q2 2026

◷ Period
Q2 2026 (Apr–Jun)
◉ Owner
Security team
▦ Grants
8 in scope
◔ Due
Jun 30, 2026
Keep0
Modify0
Revoke0
Pending8
0/8 reviewed
UserSystemRole / grantLast usedDecision
Priya Shah
AWS · prodAdministratorAccess2d ago
Marcus Lee
GitHubOrg admin6d ago
Dana Owusu
OktaSuper admin119d ago
Sam Rivera
StripeFull access4d ago
Jordan Kim
Prod databaseRead/write94d ago
ci-deploy-bot
svc · automation
AWS · prodDeployRole1h ago
Alex Chen
DatadogAdmin61d ago
Robin Patel
[email protected] (offboarded)
SalesforceStandard142d ago
Reviewer sign-off

How the review runs each quarter

Four steps, repeated every 90 days. The whole point is a defensible, dated record — not a heroic one-time cleanup.

STEP 01

Pull the grants

Export current access from each system — IdP, cloud, repos, prod DBs. Every standing grant in scope, including service accounts.

STEP 02

Route to owners

Each grant goes to the manager or system owner who can actually judge whether it's still needed. Don't self-review.

STEP 03

Decide & act

Keep, modify, or revoke. Revocations get a ticket and a timestamp. Stale grants (90+ days unused) default to revoke.

STEP 04

Sign & file

The reviewer signs off, the record is dated and stored. That artifact is your CC6.3 evidence for the audit window.

Or skip the quarterly scramble entirely

Uproot watches access continuously — flagging stale grants, dormant accounts, and over-provisioned roles the day they happen, and assembling the review record automatically. The quarterly export becomes a click, not a project.

See it liveContinuous monitoring