SOC 2
The SOC 2 access review, done right
If you’re preparing for a SOC 2 audit, the user access review is one of the controls auditors scrutinise most — and one teams most often fumble. This is a practical walkthrough of what a SOC 2 access review is, what evidence your auditor actually wants, how often to run it, and how to make it repeatable instead of a fire drill every quarter.
What the SOC 2 access review proves
SOC 2’s logical access criteria require organizations to control, authorize, modify, and remove access appropriately. Periodic user access reviews are a common control used to demonstrate that access remains appropriate over time. The access review is your evidence that someone accountable looked at every user’s access to in-scope systems and confirmed it’s still appropriate — or removed it. Access review controls commonly map to CC6.1–CC6.3.
How often to run it
Quarterly is a common cadence for privileged and production access. Lower-risk systems may be reviewed less frequently, depending on your risk assessment and control design. Whatever cadence your policy defines, consistency matters: auditors will test whether the control operated as designed.
What evidence auditors want
A spreadsheet emailed around usually fails here. Your auditor is looking for:
- A point-in-time list of every user and their access to each in-scope system — snapshotted at review time, not reconstructed later.
- A recorded decision per line (keep or revoke) by a named reviewer, with a date.
- Evidence that revocations were actually carried out.
- A clear tie between the reviewer and their authority to make the call (e.g. system owner).

Why immutable snapshots matter
The most common finding is “the evidence doesn’t match the review date.” If your review is a live query against current state, access that changed after the review makes your evidence inconsistent. Useboards snapshots each user’s access the moment a review starts and pins it — so the evidence reflects exactly what the reviewer saw, and later changes can’t contaminate it.
Doing it in Useboards
Start a review, pick the in-scope systems, and Useboards generates the snapshot. Reviewers mark each access keep or revoke with optional justification; revokes become tracked deprovisioning actions. When you’re done, export a CSV evidence pack — reviewer, decision, timestamp, and justification per line — ready to hand to your auditor.

Frequently asked questions
How often should we run a SOC 2 access review?
Quarterly is a common cadence, especially for privileged and production access; lower-risk systems may be reviewed less frequently based on your risk assessment. What matters most is running the review consistently on the cadence your policy defines, and keeping evidence for each period.
Who should perform the access review?
The person accountable for the system — typically the system or business owner — since they can judge whether access is still appropriate. The reviewer should be someone other than the person whose access is being reviewed, to preserve separation of duties.
What evidence does a SOC 2 auditor expect from an access review?
A point-in-time list of users and their access, a keep/revoke decision per line by a named reviewer with a date, and proof that revocations were completed. Auditors increasingly reject reconstructed spreadsheets in favour of snapshot-based, timestamped evidence.
Is a spreadsheet enough for a SOC 2 access review?
It can pass, but it’s fragile: no immutable snapshot, no approval trail, and easy to reconstruct after the fact — the exact things auditors question. A purpose-built review with pinned evidence removes that risk.
Related
Run an audit-ready access review
Snapshot-based evidence, CSV export for your auditor, set up in minutes.