Home · Solutions · Other solutions
Solution · Other solutionsA quarterly review that removes access, instead of a workbook that certifies it
Access reviews that reviewers finish, with the removals done
Robots collect who holds what in every in-scope system, reviewers work a short pre-sorted task in Microsoft Teams, and each approved removal is executed and evidenced by a robot the same day.
Executive summary
Quarterly access reviews eat weeks of specialist time, get approved by default and remove almost nothing.
We separate the three parts the workbook fuses together: evidence, judgement and execution.
Reviewers see thirty sorted lines with plain-language descriptions instead of nine hundred role codes, so a decision is a decision.
the same 38 systems for removals; the SharePoint evidence library; ServiceNow for disputed removals
Business problem
Access governance
An access review can fail at three points, and this one fails at all of them. Evidence: pulling who-has-what out of SAP S/4HANA, two Oracle databases, Salesforce, a warehouse system, Microsoft Entra ID and thirty SaaS consoles takes days of specialist time and yields four formats nobody can join. Reviewers: a warehouse manager cannot judge ninety technical role names, so she approves everything or nothing, and the review becomes a certification of ignorance. Follow-through: revocations are tickets, tickets queue behind incidents, and next quarter's file shows the same entitlement with a note in the comment column.
The whole control runs on a workbook with a version number. It persists because compliance owns the review, IT owns the data, the business owns the judgement, and nobody owns the outcome, which is fewer entitlements. Three IAM analysts lose most of a month per quarter to exports, and 210 managers spend an afternoon on a file that changes nothing. The auditors have noted the default approvals in the last two reports; the third is the one the CFO will have to answer.
How it works today
Four functions, one workbook, the same steps every quarter.
- PersonCompliance announces the cycle; the IAM team exports user lists from SAP, the warehouse system, Salesforce, the Oracle databases, Entra ID and the SaaS consoles, one system at a time, and pastes them into one workbook, one tab per application
- WaitingThe file goes out by email with a two-week deadline; most rows sit untouched until the reminders on day seven and day twelve
- PersonManagers approve in bulk, or not at all; on the last day compliance approves on behalf of the non-responders
- SystemRemoval requests are emailed to application owners and become ServiceNow tickets that queue behind incidents
- Risk of errorSome entitlements are removed, some are not, none of it is evidenced, and unflagged conflicts stay live in the ERP
- PersonAn evidence folder is assembled from emails and screenshots; the auditor samples it and notes the default approvals again
Why the current process costs more than it appears
Time that disappears before anyone measures it.
- Extraction is specialist time spent on formatting. Three analysts lose the better part of a month each quarter, and what they produce is a workbook, not a data set anyone can query.
- Managers who cannot read the role names approve everything or nothing, so 210 people spend hours on a decision they cannot take, and the signed result is worth less than no signature.
- Auditors read a repeated default-approval pattern as a control weakness, and one finding on access reviews costs more remediation time than a year of running the review properly.
- Removals that are nobody's job do not happen, so licences, roles and segregation-of-duties conflicts survive four reviews in a row; and the one analyst who knows every export is the control's single point of failure.
Cost of inaction
Removals are the figure missing from those rows, and it is the one the auditor reads. The review keeps consuming around three thousand hours a year and removing almost nothing; each file is larger than the last because entitlements grow with headcount and every SaaS subscription, while the team stays three people. A repeated default-approval pattern becomes a control weakness in the auditor's report, and the remediation plan lands on the CFO's desk.
Scope grows on its own: each new system adds days of extraction and one more format, the conflicts four reviews did not catch are still live in the ERP, and the analyst who knows how to extract from SAP is one resignation away from taking the control with her.
A plausible organisation with realistic proportions. The figures are there to be recalculated on your data; they are not a client result.
A pharmaceutical distributor with 2,600 employees under GxP and financial-reporting controls; SAP S/4HANA, a warehouse management system, Salesforce, two Oracle databases, Microsoft Entra ID and about thirty SaaS tools; Microsoft 365; ServiceNow for tickets.
38 applications in scope and roughly 9,400 entitlements reviewed each quarter by 210 reviewers; an IAM team of three runs the cycle, a compliance officer owns the control, auditors visit twice a year.
Entitlements are exported system by system into one workbook, emailed to managers, chased twice, approved by default for non-responders and closed; removals travel as emails and tickets; the evidence folder is assembled by hand before each audit.
About 6.5 hours of extraction, formatting and chasing per application per quarter for the IAM team, and 2.5 hours per reviewer per quarter on rows they cannot interpret; a third of reviewers never answer, and removals are rarely confirmed.
Robots extract entitlements from every in-scope system into one snapshot with last-login dates, plain-language role descriptions and conflict flags; Microsoft Entra ID access reviews handle the directory-managed part natively, every other reviewer gets one short, pre-sorted task in Microsoft Teams, and approved removals are executed by robots and evidenced line by line.
In the modelled case the IAM team's extraction hours fall by 85%, reviewer time halves because thirty sorted lines replace nine hundred codes, non-response becomes an escalation, and the auditor's pack is generated rather than assembled. The figures describe this hypothetical distributor, not a client's results.
Proposed solution
We separate the three parts the workbook fuses together: evidence, judgement and execution. Evidence is robot work: each quarter UiPath Robots extract entitlements from every in-scope system, through connectors where an API exists and through the admin console where it does not, and write a snapshot into UiPath Data Fabric (formerly Data Service) with what the workbook never had: last-login date, a plain-language description of each role from a catalogue we build with the application owners, and dormancy and segregation-of-duties flags from a rule set that compliance owns.
Judgement stays with people, but it is made short. Microsoft Entra ID access reviews cover groups, Teams and access packages natively and apply their own results; that part needs Microsoft Entra ID P2 or Microsoft Entra ID Governance for the users in scope. For everything the directory cannot see, UiPath Action Center creates one task per reviewer inside Microsoft Teams, sorted into unchanged, new, dormant and conflicting, with dormant items pre-marked for removal. Nothing is approved by silence; a reviewer who does not answer is escalated to her manager.
Execution closes the loop. Each keep-or-remove decision becomes a queue item; robots execute the removals, read the account back and write the evidence line: extraction, decision, execution, timestamp. A failed or disputed removal becomes a task for the application owner. Power BI shows completion and removals while the cycle runs, and the auditor's pack is generated from the record at close. No AI is involved; a control needs the same answer every time.
Microsoft Entra ID access reviews with results applied automatically (Microsoft Entra ID P2 or Microsoft Entra ID Governance); UiPath Orchestrator queues, credential stores and audit log; UiPath Data Fabric (formerly Data Service); UiPath Action Center tasks in Microsoft Teams; Microsoft Purview retention labels on the SharePoint evidence library; Power BI
Extraction robots (API where available, UI automation where not), the entitlement catalogue, the dormancy and conflict rules, the sorted review tasks, the removal robots with read-back verification, the evidence writer, the dashboard and the auditor's pack
SAP S/4HANA through the UiPath SAP BAPI and OData connectors and SAP activities; Salesforce and ServiceNow through UiPath Integration Service connectors; Microsoft Entra ID through Microsoft Graph; the warehouse system, the Oracle databases and the SaaS consoles through database queries and UI automation
How the automated process works
- AutomationOn day one, robots extract entitlements from all 38 systems into one snapshot in UiPath Data Fabric, with last-login dates and role descriptions attached
- AutomationThe rule set flags dormant entitlements, new grants and segregation-of-duties conflicts, and compares every line with last quarter's decision
- SystemMicrosoft Entra ID access reviews run natively for the directory-managed estate; for everything else UiPath Action Center creates one sorted task per reviewer in Microsoft Teams, with a due date and reminders
- PersonThe reviewer decides keep or remove per line inside Teams; privileged entitlements need a second decision from security; non-response escalates to the reviewer's manager
- AutomationRobots execute the approved removals the same day, read the account back and write the evidence line: extraction, decision, execution, timestamp
- PersonA failed or disputed removal becomes a task for the application owner, with the decision and the robot's error attached
- AutomationPower BI shows completion by reviewer and by system while the cycle runs; at close the auditor's pack is generated and filed as a record
Human-in-the-loop model
Automation handles
- Extracting and normalising entitlements from every in-scope system each quarter
- Flagging dormant accounts, new grants and segregation-of-duties conflicts from the versioned rule set
- Creating, reminding and escalating reviewer tasks in Microsoft Teams
- Executing approved removals, verifying them by reading the account back, and writing the evidence
People decide
- Keep or remove, per line, by the reviewer who knows the person's job
- Whether a privileged entitlement stays, with security as the second approver
- How a failed or disputed removal is resolved, by the application owner
- Scope, thresholds, conflict pairs and the sign-off of the cycle, by compliance
Before and after
Systems and integrations
Every entry can be checked in vendor documentation. The evidence class is stated next to each one.
Inputs
- SAP S/4HANA roles
- warehouse system accounts
- Salesforce profiles
- Oracle database grants
- Microsoft Entra ID groups and sign-in data
- SaaS admin consoles
- the reviewer hierarchy from HR data
Automation layer
- UiPath Orchestrator
- UiPath Robots
- UiPath Integration Service
- UiPath Data Fabric
- UiPath Action Center
Target systems
- the same 38 systems for removals
- the SharePoint evidence library
- ServiceNow for disputed removals
- Power BI
Human touchpoints: review tasks in Microsoft Teams; security's second decision on privileged entitlements; application-owner tasks for failed removals; compliance sign-off; the auditor's read access to the dashboard
Technologies used
native recertification of groups, Teams and access packages, results applied automatically
Aextraction and removal in every system; queues, credential store, audit log
Aextraction and removal through APIs where they exist; tickets for disputed removals
Athe quarterly snapshot: entitlements, last login, role descriptions, flags, decisions
Aone pre-sorted review task per reviewer, with due dates, reminders and escalation
Athe evidence library, declared as records at close
Acompletion, removals executed and conflicts closed, by reviewer and by system
AIllustrative economic model
The arithmetic is open, so it can be argued with.
Converting a quarterly cycle into monthly arithmetic is the only trick in this table; every figure is an assumption for this illustrative distributor, not a client measurement. IAM effort: 38 applications × 6.5 h × 4 quarters = 988 h a year at €58, of which 85% is robot work (840 h). Reviewer effort: 210 reviewers × 2.5 h × 4 quarters = 2,100 h a year at €77, halved by pre-sorted tasks (1,050 h). Those 1,890 automatable hours over 37,600 lines a year are about 3 minutes a line at a blended €69, and 9,400 lines a quarter are about 3,130 a month. Reclaimed licences, avoided audit remediation and the risk removed with each entitlement stay outside the model.
Run the numbers on your data
An illustrative estimate from your own inputs. It models released capacity; it is not a promise of savings.
Business benefits
- Reviewers see thirty sorted lines with plain-language descriptions instead of nine hundred role codes, so a decision is a decision
- Removals happen, because a robot executes the reviewer's choice the same day and records that it did
- Evidence is generated rather than assembled: extraction, decision, execution and timestamp exist for every entitlement
- Default approvals disappear; non-response becomes an escalation with a name on it
- Dormant entitlements surface every quarter, which finance sees as licences reclaimed and security as fewer accounts a stolen password could use
The management view
- Completion is visible by reviewer and by system while the cycle runs, so compliance chases on day three, not on day thirteen
- Entitlements removed per quarter becomes a reported figure, and conflicts are tracked to closure with an owner and a date
- Audit preparation shrinks to generating a pack, and adding a system to scope is a robot configuration and a catalogue entry, not a new tab and a new expert
Board-level KPIs
Security and governance
An auditor should be able to reconstruct every decision.
- Extraction robots hold read-only accounts; removal robots carry exactly one scoped right per system and act only on a recorded reviewer decision
- Privileged entitlements need two approvals, the reviewer and security, and break-glass accounts are excluded from the automated removal path
- Evidence goes to a SharePoint library under a Microsoft Purview retention label as a record, so it cannot be edited after the cycle closes; every robot action sits in the Orchestrator audit log, and robot passwords in its credential store
- Snapshots hold identifiers and role names, not personal content, and stay in your Microsoft 365 tenant and the EU region of UiPath Automation Cloud; rule sets are versioned per quarter, so an auditor can see which threshold applied to any decision
Why now
Two audit reports in a row have named the default approvals; the third turns a repeated pattern into a finding with a remediation plan and a deadline
Directive (EU) 2022/2555 (NIS2) expects appropriate access control policies from the entities in its scope, and GxP and financial-reporting auditors ask the same question: show that access was reviewed and revoked, not that a policy exists
Microsoft Entra ID access reviews cover the directory-managed estate natively and robots reach the consoles that have no API, which removes the last reason for a spreadsheet; the modelled €10,800 a month runs until it does
Relevant executive roles
The review starts removing access instead of documenting that it exists, and conflicts get an owner and a closure date
Three weeks of IAM specialist time per quarter come back, and one process covers every system instead of one expert per export
The control behind financial-reporting access holds up in audit, and dormant licences return to the pool every quarter
Complete evidence per entitlement, generated by the process, instead of samples and default approvals
Common questions and objections
For groups, Teams and access packages it does, and we use it. Half of your entitlements live in SAP roles, database grants and SaaS consoles the directory cannot see, and that half is where the findings come from.
They rubber-stamp nine hundred codes because there is no other way through them. Thirty sorted lines with plain descriptions and dormant items pre-marked change the default from "approve all" to "confirm the few that matter", and non-response escalates instead of counting as approval.
When it goes live, the robots hand over the connected systems and keep the ones it will never connect. Until then the review still has to run every quarter, and the catalogue and rule set are what the platform will need anyway.
When this is not the right solution
- Fewer than about ten in-scope systems, all connected to Microsoft Entra ID; native access reviews are probably enough on their own
- An identity governance platform already connected to every in-scope system, including SAP and the databases
- No usable reviewer hierarchy in HR data; the tasks would reach the wrong people, and the HR feed comes first
A question for the next management meeting
After last quarter's review of 9,400 entitlements, how many were actually removed, by whom, and could the evidence for any one of them be on this table within the hour?
Implementation approach
Delivery runs in stages, so it can be stopped at any point.
We deliver
- The control definition agreed with compliance and internal audit: scope, reviewer hierarchy, thresholds, conflict pairs, escalations
- The entitlement catalogue with plain-language role descriptions, starting with the ten systems that hold most entitlements
- Extraction robots per system, the normalised snapshot, and Microsoft Entra ID access reviews configured for the directory-managed estate
- Sorted Action Center tasks in Microsoft Teams, removal robots with read-back verification, the evidence writer, the Power BI dashboard and the auditor's pack
- One full cycle run beside the workbook so the auditor can compare, then operation of the quarterly cycle as a service if you want it
We need from you
- An owner for each in-scope application and a reviewer hierarchy from HR data
- Read access for extraction robots, one scoped administrative right per system for removal robots, and the licence position for Microsoft Entra ID access reviews
- Last quarter's completed workbook, so the first cycle can be measured against it
Stages
Discovery
Control definition with compliance and audit; catalogue for the ten largest systems; licences and access
Pilot cycle
One full quarter on SAP, Entra ID and five SaaS tools, beside the spreadsheet
Scale
The remaining systems, the conflict rules and security's second approval
Run
Quarterly cycles with completion, removals and exceptions reported to compliance
Departmental. Effort follows how many systems have no API, how much of the catalogue must be written from scratch, and whether the reviewer hierarchy in HR data is usable without an argument.
Seventy managers never replied, and the file still says the review was completed.
Share one completed review workbook from last quarter with the names removed. You get back a column-by-column read-out: what a robot would have pre-filled, what it would have executed, and which decisions still need a manager.
Test one review workbook with usThe neighbouring process usually has the same problem
Managers sign off on entitlements they cannot read, and nobody withdraws what nobody uses.
View solution IT & servicesSoftware licences reconciled every monthLeavers, duplicates and dormant accounts keep their paid seats until somebody rebuilds the list by hand.
View solution Other solutionsApplication access granted by policy in minutes, with proofAccess is granted from interpreted emails, approvals are chased, and the auditor finds the evidence missing.
View solutionIndustries we deliver this in most oftenManufacturing & industryTransport & logisticsServices & ITShared services