SOC 2

The SOC 2 access review, done right

If you’re preparing for a SOC 2 audit, the user access review is one of the controls auditors scrutinise most — and one teams most often fumble. This is a practical walkthrough of what a SOC 2 access review is, what evidence your auditor actually wants, how often to run it, and how to make it repeatable instead of a fire drill every quarter.

What the SOC 2 access review proves

SOC 2’s logical access criteria require organizations to control, authorize, modify, and remove access appropriately. Periodic user access reviews are a common control used to demonstrate that access remains appropriate over time. The access review is your evidence that someone accountable looked at every user’s access to in-scope systems and confirmed it’s still appropriate — or removed it. Access review controls commonly map to CC6.1–CC6.3.

How often to run it

Quarterly is a common cadence for privileged and production access. Lower-risk systems may be reviewed less frequently, depending on your risk assessment and control design. Whatever cadence your policy defines, consistency matters: auditors will test whether the control operated as designed.

What evidence auditors want

A spreadsheet emailed around usually fails here. Your auditor is looking for:

  • A point-in-time list of every user and their access to each in-scope system — snapshotted at review time, not reconstructed later.
  • A recorded decision per line (keep or revoke) by a named reviewer, with a date.
  • Evidence that revocations were actually carried out.
  • A clear tie between the reviewer and their authority to make the call (e.g. system owner).
Useboards reports and evidence export for a SOC 2 access review
Export a CSV evidence pack — reviewer, decision, timestamp, and justification per line.

Why immutable snapshots matter

The most common finding is “the evidence doesn’t match the review date.” If your review is a live query against current state, access that changed after the review makes your evidence inconsistent. Useboards snapshots each user’s access the moment a review starts and pins it — so the evidence reflects exactly what the reviewer saw, and later changes can’t contaminate it.

Doing it in Useboards

Start a review, pick the in-scope systems, and Useboards generates the snapshot. Reviewers mark each access keep or revoke with optional justification; revokes become tracked deprovisioning actions. When you’re done, export a CSV evidence pack — reviewer, decision, timestamp, and justification per line — ready to hand to your auditor.

A user access review in Useboards with keep/revoke decisions per line
Each access is reviewed keep or revoke, against a snapshot pinned at review-start.

Frequently asked questions

How often should we run a SOC 2 access review?

Quarterly is a common cadence, especially for privileged and production access; lower-risk systems may be reviewed less frequently based on your risk assessment. What matters most is running the review consistently on the cadence your policy defines, and keeping evidence for each period.

Who should perform the access review?

The person accountable for the system — typically the system or business owner — since they can judge whether access is still appropriate. The reviewer should be someone other than the person whose access is being reviewed, to preserve separation of duties.

What evidence does a SOC 2 auditor expect from an access review?

A point-in-time list of users and their access, a keep/revoke decision per line by a named reviewer with a date, and proof that revocations were completed. Auditors increasingly reject reconstructed spreadsheets in favour of snapshot-based, timestamped evidence.

Is a spreadsheet enough for a SOC 2 access review?

It can pass, but it’s fragile: no immutable snapshot, no approval trail, and easy to reconstruct after the fact — the exact things auditors question. A purpose-built review with pinned evidence removes that risk.

Related

Run an audit-ready access review

Snapshot-based evidence, CSV export for your auditor, set up in minutes.