Home · Solutions · Other solutions

Solution · Other solutions

A quarterly review that removes access, instead of a workbook that certifies it

Access reviews that reviewers finish, with the removals done

Robots collect who holds what in every in-scope system, reviewers work a short pre-sorted task in Microsoft Teams, and each approved removal is executed and evidenced by a robot the same day.

DepartmentalMicrosoft TeamsHuman in the loopDeterministic automation
9,400lines, one tab per application, go to 210 managers every quarter at this illustrative pharmaceutical distributor. Almost nothing is ever removed.

Executive summary

Challenge

Quarterly access reviews eat weeks of specialist time, get approved by default and remove almost nothing.

What changes

We separate the three parts the workbook fuses together: evidence, judgement and execution.

Business value

Reviewers see thirty sorted lines with plain-language descriptions instead of nine hundred role codes, so a decision is a decision.

Systems involved

the same 38 systems for removals; the SharePoint evidence library; ServiceNow for disputed removals

Business problem

Access governance

An access review can fail at three points, and this one fails at all of them. Evidence: pulling who-has-what out of SAP S/4HANA, two Oracle databases, Salesforce, a warehouse system, Microsoft Entra ID and thirty SaaS consoles takes days of specialist time and yields four formats nobody can join. Reviewers: a warehouse manager cannot judge ninety technical role names, so she approves everything or nothing, and the review becomes a certification of ignorance. Follow-through: revocations are tickets, tickets queue behind incidents, and next quarter's file shows the same entitlement with a note in the comment column.

The whole control runs on a workbook with a version number. It persists because compliance owns the review, IT owns the data, the business owns the judgement, and nobody owns the outcome, which is fewer entitlements. Three IAM analysts lose most of a month per quarter to exports, and 210 managers spend an afternoon on a file that changes nothing. The auditors have noted the default approvals in the last two reports; the third is the one the CFO will have to answer.

How it works today

Four functions, one workbook, the same steps every quarter.

  1. PersonCompliance announces the cycle; the IAM team exports user lists from SAP, the warehouse system, Salesforce, the Oracle databases, Entra ID and the SaaS consoles, one system at a time, and pastes them into one workbook, one tab per application
  2. WaitingThe file goes out by email with a two-week deadline; most rows sit untouched until the reminders on day seven and day twelve
  3. PersonManagers approve in bulk, or not at all; on the last day compliance approves on behalf of the non-responders
  4. SystemRemoval requests are emailed to application owners and become ServiceNow tickets that queue behind incidents
  5. Risk of errorSome entitlements are removed, some are not, none of it is evidenced, and unflagged conflicts stay live in the ERP
  6. PersonAn evidence folder is assembled from emails and screenshots; the auditor samples it and notes the default approvals again
PersonWaitingSystemRisk of error

Why the current process costs more than it appears

Time that disappears before anyone measures it.

  • Extraction is specialist time spent on formatting. Three analysts lose the better part of a month each quarter, and what they produce is a workbook, not a data set anyone can query.
  • Managers who cannot read the role names approve everything or nothing, so 210 people spend hours on a decision they cannot take, and the signed result is worth less than no signature.
  • Auditors read a repeated default-approval pattern as a control weakness, and one finding on access reviews costs more remediation time than a year of running the review properly.
  • Removals that are nobody's job do not happen, so licences, roles and segregation-of-duties conflicts survive four reviews in a row; and the one analyst who knows every export is the control's single point of failure.

Cost of inaction

Four more cycles run from the workbook, automatable share only (per year)≈ €129,600
Twelve cycles, the span of six audit visits, at today's pace≈ €388,800
One year once scope reaches 50 applications and 260 reviewers≈ €164,200

Removals are the figure missing from those rows, and it is the one the auditor reads. The review keeps consuming around three thousand hours a year and removing almost nothing; each file is larger than the last because entitlements grow with headcount and every SaaS subscription, while the team stays three people. A repeated default-approval pattern becomes a control weakness in the auditor's report, and the remediation plan lands on the CFO's desk.

Scope grows on its own: each new system adds days of extraction and one more format, the conflicts four reviews did not catch are still live in the ERP, and the analyst who knows how to extract from SAP is one resignation away from taking the control with her.

Illustrative scenario

A plausible organisation with realistic proportions. The figures are there to be recalculated on your data; they are not a client result.

Organisation

A pharmaceutical distributor with 2,600 employees under GxP and financial-reporting controls; SAP S/4HANA, a warehouse management system, Salesforce, two Oracle databases, Microsoft Entra ID and about thirty SaaS tools; Microsoft 365; ServiceNow for tickets.

Volume

38 applications in scope and roughly 9,400 entitlements reviewed each quarter by 210 reviewers; an IAM team of three runs the cycle, a compliance officer owns the control, auditors visit twice a year.

Current process

Entitlements are exported system by system into one workbook, emailed to managers, chased twice, approved by default for non-responders and closed; removals travel as emails and tickets; the evidence folder is assembled by hand before each audit.

Bottleneck

About 6.5 hours of extraction, formatting and chasing per application per quarter for the IAM team, and 2.5 hours per reviewer per quarter on rows they cannot interpret; a third of reviewers never answer, and removals are rarely confirmed.

Solution

Robots extract entitlements from every in-scope system into one snapshot with last-login dates, plain-language role descriptions and conflict flags; Microsoft Entra ID access reviews handle the directory-managed part natively, every other reviewer gets one short, pre-sorted task in Microsoft Teams, and approved removals are executed by robots and evidenced line by line.

Potential outcome

In the modelled case the IAM team's extraction hours fall by 85%, reviewer time halves because thirty sorted lines replace nine hundred codes, non-response becomes an escalation, and the auditor's pack is generated rather than assembled. The figures describe this hypothetical distributor, not a client's results.

Proposed solution

We separate the three parts the workbook fuses together: evidence, judgement and execution. Evidence is robot work: each quarter UiPath Robots extract entitlements from every in-scope system, through connectors where an API exists and through the admin console where it does not, and write a snapshot into UiPath Data Fabric (formerly Data Service) with what the workbook never had: last-login date, a plain-language description of each role from a catalogue we build with the application owners, and dormancy and segregation-of-duties flags from a rule set that compliance owns.

Judgement stays with people, but it is made short. Microsoft Entra ID access reviews cover groups, Teams and access packages natively and apply their own results; that part needs Microsoft Entra ID P2 or Microsoft Entra ID Governance for the users in scope. For everything the directory cannot see, UiPath Action Center creates one task per reviewer inside Microsoft Teams, sorted into unchanged, new, dormant and conflicting, with dormant items pre-marked for removal. Nothing is approved by silence; a reviewer who does not answer is escalated to her manager.

Execution closes the loop. Each keep-or-remove decision becomes a queue item; robots execute the removals, read the account back and write the evidence line: extraction, decision, execution, timestamp. A failed or disputed removal becomes a task for the application owner. Power BI shows completion and removals while the cycle runs, and the auditor's pack is generated from the record at close. No AI is involved; a control needs the same answer every time.

Native capabilities used

Microsoft Entra ID access reviews with results applied automatically (Microsoft Entra ID P2 or Microsoft Entra ID Governance); UiPath Orchestrator queues, credential stores and audit log; UiPath Data Fabric (formerly Data Service); UiPath Action Center tasks in Microsoft Teams; Microsoft Purview retention labels on the SharePoint evidence library; Power BI

What we build

Extraction robots (API where available, UI automation where not), the entitlement catalogue, the dormancy and conflict rules, the sorted review tasks, the removal robots with read-back verification, the evidence writer, the dashboard and the auditor's pack

Custom integration

SAP S/4HANA through the UiPath SAP BAPI and OData connectors and SAP activities; Salesforce and ServiceNow through UiPath Integration Service connectors; Microsoft Entra ID through Microsoft Graph; the warehouse system, the Oracle databases and the SaaS consoles through database queries and UI automation

How the automated process works

  1. AutomationOn day one, robots extract entitlements from all 38 systems into one snapshot in UiPath Data Fabric, with last-login dates and role descriptions attached
  2. AutomationThe rule set flags dormant entitlements, new grants and segregation-of-duties conflicts, and compares every line with last quarter's decision
  3. SystemMicrosoft Entra ID access reviews run natively for the directory-managed estate; for everything else UiPath Action Center creates one sorted task per reviewer in Microsoft Teams, with a due date and reminders
  4. PersonThe reviewer decides keep or remove per line inside Teams; privileged entitlements need a second decision from security; non-response escalates to the reviewer's manager
  5. AutomationRobots execute the approved removals the same day, read the account back and write the evidence line: extraction, decision, execution, timestamp
  6. PersonA failed or disputed removal becomes a task for the application owner, with the decision and the robot's error attached
  7. AutomationPower BI shows completion by reviewer and by system while the cycle runs; at close the auditor's pack is generated and filed as a record
AutomationSystemPerson

Human-in-the-loop model

Automation handles

  • Extracting and normalising entitlements from every in-scope system each quarter
  • Flagging dormant accounts, new grants and segregation-of-duties conflicts from the versioned rule set
  • Creating, reminding and escalating reviewer tasks in Microsoft Teams
  • Executing approved removals, verifying them by reading the account back, and writing the evidence

People decide

  • Keep or remove, per line, by the reviewer who knows the person's job
  • Whether a privileged entitlement stays, with security as the second approver
  • How a failed or disputed removal is resolved, by the application owner
  • Scope, thresholds, conflict pairs and the sign-off of the cycle, by compliance

Before and after

BeforeAfter
IAM effort per application per quarter6.5 h of exports, paste-ups and chasingrobot extraction; minutes to check the snapshot
What a reviewer receiveshundreds of rows of role codesthirty sorted lines with plain-language descriptions, in Teams
Non-responseapproved by default on the last dayescalated to the reviewer's manager; nothing approved by silence
Removals and their evidenceemailed requests, half never confirmedexecuted by robots the same day, evidenced per line

Systems and integrations

Every entry can be checked in vendor documentation. The evidence class is stated next to each one.

Inputs

  • SAP S/4HANA roles
  • warehouse system accounts
  • Salesforce profiles
  • Oracle database grants
  • Microsoft Entra ID groups and sign-in data
  • SaaS admin consoles
  • the reviewer hierarchy from HR data

Automation layer

  • UiPath Orchestrator
  • UiPath Robots
  • UiPath Integration Service
  • UiPath Data Fabric
  • UiPath Action Center

Target systems

  • the same 38 systems for removals
  • the SharePoint evidence library
  • ServiceNow for disputed removals
  • Power BI

Human touchpoints: review tasks in Microsoft Teams; security's second decision on privileged entitlements; application-owner tasks for failed removals; compliance sign-off; the auditor's read access to the dashboard

SAP S/4HANA rolesUiPath OrchestratorUiPath Robotsthe same 38 systems for removalsreview tasks in Microsoft Teams

Technologies used

Microsoft Entra ID access reviews (Microsoft Entra ID Governance)

native recertification of groups, Teams and access packages, results applied automatically

A
UiPath Robots + Orchestrator

extraction and removal in every system; queues, credential store, audit log

A
UiPath Integration Service (SAP, Salesforce, ServiceNow and Microsoft Teams connectors; Microsoft Graph identity data)

extraction and removal through APIs where they exist; tickets for disputed removals

A
UiPath Data Fabric (formerly Data Service)

the quarterly snapshot: entitlements, last login, role descriptions, flags, decisions

A
UiPath Action Center in Microsoft Teams

one pre-sorted review task per reviewer, with due dates, reminders and escalation

A
Microsoft SharePoint with Microsoft Purview retention labels

the evidence library, declared as records at close

A
Power BI

completion, removals executed and conflicts closed, by reviewer and by system

A
Averified product capability (vendor documentation)

Illustrative economic model

The arithmetic is open, so it can be argued with.

Illustrative model
3,130 entitlement lines a month × 3 minutes of automatable handling per line= 157 h / month
157 h × €69 blended fully loaded hourly cost≈ €10,800 / month
× 12 months≈ €129,600 / year
Annual capacity released across the IAM team and the reviewers (illustrative)≈ €129,600

Converting a quarterly cycle into monthly arithmetic is the only trick in this table; every figure is an assumption for this illustrative distributor, not a client measurement. IAM effort: 38 applications × 6.5 h × 4 quarters = 988 h a year at €58, of which 85% is robot work (840 h). Reviewer effort: 210 reviewers × 2.5 h × 4 quarters = 2,100 h a year at €77, halved by pre-sorted tasks (1,050 h). Those 1,890 automatable hours over 37,600 lines a year are about 3 minutes a line at a blended €69, and 9,400 lines a quarter are about 3,130 a month. Reclaimed licences, avoided audit remediation and the risk removed with each entitlement stay outside the model.

Run the numbers on your data

hours released per month
of annual capacity released

An illustrative estimate from your own inputs. It models released capacity; it is not a promise of savings.

Business benefits

  • Reviewers see thirty sorted lines with plain-language descriptions instead of nine hundred role codes, so a decision is a decision
  • Removals happen, because a robot executes the reviewer's choice the same day and records that it did
  • Evidence is generated rather than assembled: extraction, decision, execution and timestamp exist for every entitlement
  • Default approvals disappear; non-response becomes an escalation with a name on it
  • Dormant entitlements surface every quarter, which finance sees as licences reclaimed and security as fewer accounts a stolen password could use

The management view

  • Completion is visible by reviewer and by system while the cycle runs, so compliance chases on day three, not on day thirteen
  • Entitlements removed per quarter becomes a reported figure, and conflicts are tracked to closure with an owner and a date
  • Audit preparation shrinks to generating a pack, and adding a system to scope is a robot configuration and a catalogue entry, not a new tab and a new expert

Board-level KPIs

review completion without default approvalsentitlements removed per cycleremovals executed within five days of the decisionopen segregation-of-duties conflictsIAM hours per cycleaudit exceptions on access reviews

Security and governance

An auditor should be able to reconstruct every decision.

  • Extraction robots hold read-only accounts; removal robots carry exactly one scoped right per system and act only on a recorded reviewer decision
  • Privileged entitlements need two approvals, the reviewer and security, and break-glass accounts are excluded from the automated removal path
  • Evidence goes to a SharePoint library under a Microsoft Purview retention label as a record, so it cannot be edited after the cycle closes; every robot action sits in the Orchestrator audit log, and robot passwords in its credential store
  • Snapshots hold identifiers and role names, not personal content, and stay in your Microsoft 365 tenant and the EU region of UiPath Automation Cloud; rule sets are versioned per quarter, so an auditor can see which threshold applied to any decision

Why now

01

Two audit reports in a row have named the default approvals; the third turns a repeated pattern into a finding with a remediation plan and a deadline

02

Directive (EU) 2022/2555 (NIS2) expects appropriate access control policies from the entities in its scope, and GxP and financial-reporting auditors ask the same question: show that access was reviewed and revoked, not that a policy exists

03

Microsoft Entra ID access reviews cover the directory-managed estate natively and robots reach the consoles that have no API, which removes the last reason for a spreadsheet; the modelled €10,800 a month runs until it does

Relevant executive roles

CISO

The review starts removing access instead of documenting that it exists, and conflicts get an owner and a closure date

CIO

Three weeks of IAM specialist time per quarter come back, and one process covers every system instead of one expert per export

CFO

The control behind financial-reporting access holds up in audit, and dormant licences return to the pool every quarter

Head of Internal Audit

Complete evidence per entitlement, generated by the process, instead of samples and default approvals

Common questions and objections

Microsoft Entra ID already does access reviews.

For groups, Teams and access packages it does, and we use it. Half of your entitlements live in SAP roles, database grants and SaaS consoles the directory cannot see, and that half is where the findings come from.

Managers will still rubber-stamp.

They rubber-stamp nine hundred codes because there is no other way through them. Thirty sorted lines with plain descriptions and dormant items pre-marked change the default from "approve all" to "confirm the few that matter", and non-response escalates instead of counting as approval.

Our identity governance project will cover this.

When it goes live, the robots hand over the connected systems and keep the ones it will never connect. Until then the review still has to run every quarter, and the catalogue and rule set are what the platform will need anyway.

When this is not the right solution

  • Fewer than about ten in-scope systems, all connected to Microsoft Entra ID; native access reviews are probably enough on their own
  • An identity governance platform already connected to every in-scope system, including SAP and the databases
  • No usable reviewer hierarchy in HR data; the tasks would reach the wrong people, and the HR feed comes first

A question for the next management meeting

After last quarter's review of 9,400 entitlements, how many were actually removed, by whom, and could the evidence for any one of them be on this table within the hour?

Implementation approach

Delivery runs in stages, so it can be stopped at any point.

We deliver

  • The control definition agreed with compliance and internal audit: scope, reviewer hierarchy, thresholds, conflict pairs, escalations
  • The entitlement catalogue with plain-language role descriptions, starting with the ten systems that hold most entitlements
  • Extraction robots per system, the normalised snapshot, and Microsoft Entra ID access reviews configured for the directory-managed estate
  • Sorted Action Center tasks in Microsoft Teams, removal robots with read-back verification, the evidence writer, the Power BI dashboard and the auditor's pack
  • One full cycle run beside the workbook so the auditor can compare, then operation of the quarterly cycle as a service if you want it

We need from you

  • An owner for each in-scope application and a reviewer hierarchy from HR data
  • Read access for extraction robots, one scoped administrative right per system for removal robots, and the licence position for Microsoft Entra ID access reviews
  • Last quarter's completed workbook, so the first cycle can be measured against it

Stages

Discovery

Control definition with compliance and audit; catalogue for the ten largest systems; licences and access

Pilot cycle

One full quarter on SAP, Entra ID and five SaaS tools, beside the spreadsheet

Scale

The remaining systems, the conflict rules and security's second approval

Run

Quarterly cycles with completion, removals and exceptions reported to compliance

Departmental. Effort follows how many systems have no API, how much of the catalogue must be written from scratch, and whether the reviewer hierarchy in HR data is usable without an argument.