By NHI Mgmt Group Editorial TeamBased on Zluri: “Zluri for Zluri: How We Do User Access Review at Zluri” (October 13, 2025)

TL;DR: Access review programmes fail when they depend on manual coordination instead of governed, auditable decision loops, according to Zluri. It describes how it automates user access review workflows for applications such as Salesforce, combining auto-discovery, multi-level certification, bulk reviewer actions, and closed-loop remediation to support compliance and least privilege across sensitive business systems.


At a glance

What this is: This is an IAM and IGA walkthrough of how Zluri automates user access reviews for business applications, using Salesforce as the example and emphasizing discovery, certification, remediation, and audit reporting.

Why it matters: It matters because access review programmes only work when reviewers can make timely, evidence-backed decisions and those decisions are actually enforced across human and non-human access paths.


Context

User access review automation is the control layer that turns entitlement review from a periodic spreadsheet exercise into a governed decision process. In this article, the primary IAM problem is not discovery alone, but proving that the right people retain only the access they still need across systems that hold sensitive data.

Zluri frames the issue through its own internal use of user access reviews, with Salesforce used as the example application. The operational question for IAM and IGA teams is whether reviews can be completed, evidenced, and remediated fast enough to support compliance and least-privilege enforcement without relying on manual coordination.

For identity programmes, the important shift is from asking who should review access to asking whether the review loop itself is auditable, repeatable, and enforceable. That is the boundary between a governance process and a paper process.


Key questions

Q: How should IAM teams govern access reviews across multiple systems?

A: They should define one accountable review owner, one evidence standard, and one remediation path that applies across every connected directory, SaaS platform, and on-prem system. If the review cannot trigger action in all downstream systems, it only measures governance. Consistency matters more than review volume.

Q: Why do manual access review reports fail in practice?

A: Manual reports fail because reviewers must reconcile apps, identities, permissions, and remediation actions while the environment keeps changing. That creates errors, missed entitlements, and inconsistent evidence. The result is a report that may document activity but cannot reliably prove governance outcome or control effectiveness.

Q: How do you know if an access review programme is actually working?

A: Look beyond completion rate. A working programme shows fast detection-to-remediation time, meaningful percentages of access changed or revoked, and low rates of blanket approval from reviewers. If identified risk remains open for weeks or audit evidence is hard to reconstruct, the programme is producing activity but not control.

Q: When should organisations move from manual recertification to automated access reviews?

A: Organisations should move as soon as manual recertification starts slowing down approvals, creating inconsistent decisions, or leaving too little time before audit deadlines. Automation is especially justified when the same users must be reviewed across SAP and multiple connected applications. At that point, workflow standardisation, risk scoring, and faster remediation materially improve control quality.


Technical breakdown

Auto-discovery and entitlement mapping for access reviews

User access review automation starts with continuously collecting who has access, what roles they hold, and when they last used the application. In practice, that means building a current entitlement inventory from direct integrations rather than asking app owners to reconstruct access from memory. The technical value is not only visibility. It is the ability to anchor review decisions to live entitlement data, which is essential when applications like Salesforce support multiple roles and permission patterns across business teams.

Practical implication: connect certification workflows to live entitlement data so reviewers are validating current access, not stale exports.

Certification workflows, reviewer tiers, and decision control

A certification campaign formalises who owns the review, who performs it, and how decisions move through multiple levels. Zluri describes certification owners, reviewer assignment, layered review levels, and mandatory comments for revoke or modify actions. That structure matters because access reviews fail when there is no clear decision authority or when approval chains are too loose to produce defensible audit evidence. The mechanism here is governance by workflow, not by reminder email.

Practical implication: define reviewer ownership and decision rules before the campaign starts, or the review will stall at the point of accountability.

Closed-loop remediation and audit-ready reporting

The control only becomes real when review decisions trigger downstream change. Closed-loop remediation links revoke or modify outcomes to a playbook that changes access immediately, while reporting preserves timestamps, comments, and reviewer actions in an audit-ready record. That separation between decision and enforcement is where many access review programmes break down. A review without enforced remediation is only a recommendation, not an access control.

Practical implication: require every revoke or modify outcome to produce an automated entitlement change and a durable audit trail.


NHI Mgmt Group analysis

Access review automation is governance infrastructure, not admin convenience. The article shows that user access reviews only become operationally useful when discovery, certification, remediation, and reporting are tied together in one governed loop. That is the difference between proving control and merely tracking intent. For IAM and IGA teams, the review process itself has to be treated as a control surface.

Manual certification breaks down at the point of evidence, not just effort. Spreadsheets and email chains do more than slow the process. They weaken the chain between who decided, what they decided, and whether the entitlement actually changed. Auditability depends on that chain remaining intact, which is why review programmes need workflow enforcement rather than offline coordination.

Closed-loop remediation is the real least-privilege control. A review that ends with approval or revocation on paper does not reduce risk unless entitlement state is changed in the application. Least privilege is therefore an operational property of the governance loop, not a policy statement. Teams should measure whether decisions actually reach the target system, not just whether the campaign closed.

Access review programmes now have to account for human and non-human entitlement sprawl together. The same governance pattern that reviews employee access also needs to handle service accounts, app integrations, and other non-human access where appropriate. As identity estates become more mixed, access review design has to reflect the full entitlement graph, not just the human user directory.

Audit-ready reporting is a control outcome, not a postscript. Regulators and auditors do not only care that a review occurred. They care that the decision path, timestamps, comments, and remediation evidence are complete enough to support accountability. The programme implication is simple: if reporting cannot prove the control operated end to end, the control was incomplete.

What this signals

Review automation is now a governance requirement for high-churn application estates. When entitlement volumes and audit expectations rise together, manual certification becomes a control bottleneck rather than a safeguard. Programmes need workflows that combine reviewer context, mandatory evidence, and enforced remediation in one path.

Closed-loop access review is the decisive control pattern. A decision that does not change access in the source application is not a completed governance action. IAM and IGA teams should design for enforced entitlement change, not just completed review tickets.


For practitioners

  • Standardise certification ownership Assign a named certification owner for every access review campaign and define who can override decisions at each level of review.
  • Pull review data from live entitlement sources Integrate the review workflow directly with application and HR data so reviewers see current access, role, and usage context.
  • Require closed-loop remediation Automate revoke and modify actions so reviewer decisions change access in the target system instead of remaining as audit notes.
  • Enforce evidence for every non-approval decision Make comments mandatory when a reviewer revokes or modifies access so the audit trail explains the business reason behind the change.
  • Schedule recurring access reviews by application risk Set monthly, quarterly, or yearly recurrence based on the sensitivity of the application and the pace of entitlement change.

Key takeaways

  • User access review programmes fail when the review process is disconnected from current entitlement data and downstream enforcement.
  • The operational value comes from linking discovery, reviewer decisions, remediation, and audit evidence into one controlled workflow.
  • IAM teams should treat access review automation as a governance control that must change access state, not merely document intent.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is about governed review of access permissions and entitlement changes.
Recommendation — Use PR.AA-05 to ensure access reviews verify, approve, and revoke entitlements in a controlled workflow.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeThe article centers on sustaining least privilege through recurring access review decisions.
IA-5 — Authenticator ManagementReview automation often feeds credential and account hygiene controls tied to access changes.
Recommendation — Apply AC-6 to remove unnecessary access after review decisions and keep privilege bounded to need. Tie review outcomes to IA-5 processes so access changes are enforced and stale credentials are removed.
CIS Controls v8CIS-5 — Account ManagementThe workflow manages who retains access and how account changes are evidenced.
Recommendation — Use CIS-5 to standardise account review, approval, and removal workflows across business applications.
ISO/IEC 27001:2022A.5.18 — Access RightsISO 27001 access-rights governance aligns directly with periodic user access reviews and revocation.
Recommendation — Use A.5.18 to review and revoke access rights on a recurring, evidence-backed schedule.

Key terms

  • User Access Review: A user access review is a periodic check that confirms each account still needs the access it has. In identity programs, the control is used to reduce excess privilege, support compliance, and catch access that has outlived its business need.
  • Certification Campaign: A certification campaign is a structured access review in which owners confirm whether an identity still needs its permissions. For NHIs, the review must include purpose, actual usage, privilege scope, and ownership because role-based human review logic does not map cleanly to automation.
  • Closed-Loop Remediation: A governance process that does not stop at finding risk. It removes or reduces access, confirms the change in the source systems, and keeps evidence that the risky condition stayed fixed. For NHIs, this is the difference between inventory and actual risk reduction.
  • Least Privilege: A security principle requiring that every identity, human or non-human, is granted only the minimum permissions necessary to perform its function. Least privilege is the single most effective control for reducing NHI blast radius.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org