JHED Access Reviews: Why Permissions Need Regular Reassessment
Granting access is only one part of access management.
The other question is whether the access should still exist.
Over time, people change roles, departments, projects and responsibilities. Applications change ownership. Temporary access can become permanent simply because no one reviews it.
This creates a gap between:
Access that was once approved
and
Access that is still necessary
A regular access review is designed to close that gap.
Why permissions become outdated
Permissions can remain active for many reasons.
A user may:
- change departments;
- move into a new role;
- complete a temporary project;
- lose a business responsibility;
- become inactive in a particular application;
- return to the institution under a different role.
The underlying JHED identity may remain valid throughout these changes.
That does not mean every previous application permission remains appropriate.
Identity persistence can hide access drift
A persistent institutional identity is useful because the person does not need a completely new digital identity for every role change.
However, this creates a governance challenge.
If an identity survives multiple organizational changes, older permissions can follow the person unless systems and administrators actively review them.
This gradual accumulation of unnecessary access can be described as permission drift.
The user may not even know that older permissions remain active.
What an access review asks
An access review does not necessarily ask whether the person is still employed.
It asks more specific questions:
- Does this user still need this application?
- Does the current role justify the permission?
- Is the original business purpose still valid?
- Does the department still own the resource?
- Has temporary access expired?
- Should access be changed, retained or removed?
This makes access review a business and governance process as much as a technical process.
Different access can require different review approaches
Not every permission carries the same level of risk.
For example:
Low-sensitivity collaboration access may have different review requirements from:
access to sensitive administrative systems.
A useful review program can prioritize:
- highly sensitive applications;
- privileged accounts;
- external collaborators;
- temporary access;
- users who recently changed roles;
- accounts with no recent business justification.
The exact model should reflect the institution’s policies and resource ownership.
Who should review access?
A central identity team may know that an account exists.
It may not know whether the user’s day-to-day responsibilities still require every application.
Application owners and business managers often have more context about the permission itself.
A useful division of responsibility can therefore be:
Identity team: maintains the identity framework.
Application owner: understands the resource.
Manager or department: understands the user’s business need.
Access administrator: implements approved changes.
This shared model is why access governance cannot be solved through one centralized team alone.
Review events can be as important as review schedules
Some access should not wait for an annual review.
A review may be triggered when a person:
- changes jobs;
- transfers departments;
- finishes a project;
- changes from employee to external collaborator;
- leaves an institutional role;
- receives a new privileged function.
Event-driven reviews can help prevent permissions from surviving major organizational changes.
What happens after a review?
An effective review should lead to an action.
Possible outcomes include:
- retain access;
- remove access;
- reduce privileges;
- transfer ownership;
- update the access record;
- confirm that a temporary relationship has ended.
A review that produces no clear ownership or action may not reduce the underlying risk.
Access review is not punishment
Users sometimes view access removal as a technical failure.
In many cases, removing obsolete access is simply part of normal lifecycle management.
The purpose is to keep the user’s current permissions aligned with the current institutional role.
That is better than allowing access to accumulate indefinitely.
The central principle
A JHED identity can remain legitimate while individual permissions become outdated.
That is why identity review and access review are related but different processes.
The identity answers:
Is this still the same person in the institutional environment?
The access review asks:
Should this person still have this specific permission?
Both questions matter.
Related articles:
- The JHED Account Lifecycle
- Role Changes and Permission Drift
- JHED Access Governance
- External Collaborator Access