Governance · IT Governance
Access Governance
Ensuring that access rights are justified, approved, reviewed and removed across every system.
IntermediateUpdated 2026-09-01
Overview
Access governance covers the approval model for entitlements, periodic certification by managers or system owners, separation of duties rules, and prompt removal on role change or departure.
It only works with an accurate application inventory. Systems outside SSO and outside the review cycle are where accumulated, forgotten access lives.
Security considerations
- Review privileged and third party access more frequently than standard access.
- Measure and report removal timeliness for leavers as a control metric.
