## TL;DR
Each quarter, pull the access list for in-scope systems, send each manager their team's access to review, revoke what is rejected, and track completion. Helpdesk's role is the machinery: lists, reminders, revocations, and evidence. Start with one system and expand.

## The error
```text
(Recurring compliance task; no error.)
```

## Steps
1. Scope the quarter: pick the systems (start with the riskiest: finance, HR, production). Expected: scoped list. Reviewing everything every quarter burns everyone out.
2. Pull current access: group memberships, app assignments, shared folder ACLs. Expected: per-manager lists. Automate the pull; manual lists do not scale.
3. Send each manager their team's access with a clear deadline and a simple approve/revoke choice per line. Expected: sent. Make the UI easy; managers will not fight a bad spreadsheet.
4. Process revocations within a week of responses. Expected: revoked. A review without revocation is theater.
5. Chase non-responders, escalate after the deadline, and file the evidence (who reviewed, what changed). Expected: complete package for auditors.

## When to use
- Quarterly access reviews
- SOC 2 / ISO 27001 evidence

## When not to use
- Privileged admin reviews (deeper process)
- Real-time provisioning decisions

## Compatibility
- Any identity system; the process is tool-agnostic

## Variants
### Small company
The helpdesk lead can review directly with department heads in a meeting.
### Large company
Automate with access-review tooling (Entra access reviews, Okta governance).

## Why it happens
Permissions only accumulate. The quarterly review is the counterweight, and helpdesk runs it because helpdesk owns the provisioning machinery.

## Edge cases
- Shared accounts and service accounts need owners assigned before they can be reviewed.
- Do not let "approved" become the default; require an active choice per line.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_ahhc_jzPsboFBrYEsfv9Pw
