Joopler docs
Run your program

Access reviews

Certify who has access to your systems each quarter, straight from your live identity data.

Each period, confirm that access to your systems is still appropriate. Joopler pulls the real account list from your connected identity provider, so you review actual access, not a stale spreadsheet.

Run a review

  1. Start the review for the current quarter. Joopler loads the live roster of accounts from your connected systems.
  2. For each account, decide keep or revoke, based on whether the person still needs that access.
  3. Complete the review once every account has a decision.

Each keep/revoke decision is signed into the attestation, so the review is an evidence-backed record of who reviewed what and when, not a checkbox.

Every review has a due date

A review is due at the end of its period - the Q3 review is due 30 September. The review shows its due date and how long is left, so "we are behind on access reviews" is something you see in advance rather than discover during an audit.

Deciding to revoke is not revoking

Marking an account revoke records your decision. It does not reach into your identity provider and remove the access - Joopler reads your systems, it does not change them.

So each revoke decision is raised as a finding in your findings register, open until somebody confirms the access was actually removed. That closes the gap between a review that says access was revoked and an identity provider where the account still works, which is one of the more common things an auditor finds.

Why it matters

A completed review for the current period passes the access-review control, which several frameworks require (SOC 2 CC6, ISO 27001, HIPAA, PCI Requirement 7). The control is graded from your actual review records - whether one exists for the period, whether it was completed, and whether it was completed on time - not from a box you tick somewhere else. A missing or overdue review shows up as a failing control with a prompt to run one.