What an IAM review actually covers
A plain-language walkthrough of evidence, interviews, and findings — without burying you in product feature lists.
When organisations ask for an identity and access management review, they often expect a tool inventory. The useful work sits elsewhere: who can reach which systems, how those rights were granted, and whether anyone still needs them.
A typical engagement starts with the identity sources that matter — directory services, HR feeds, federation brokers, and the admin portals for critical applications. We map those sources before sampling accounts, because sampling without a map produces noise.
Interviews matter as much as exports. Service desk staff describe how transfers are handled in practice; application owners explain which roles are never revoked; finance leads flag combinations of duties that should never sit with one person.
Findings are written as decisions you can assign. Severity reflects business exposure, not only technical elegance. A dormant domain admin account ranks higher than an unused marketing role — even if both violate policy.
The closing workshop is where the review earns its keep. Owners leave with a sequenced list: revoke, recertify, redesign, or accept with a named risk owner. That sequence is what auditors and boards can follow.