TL;DR: C1.ai argues that user access reviews should do more than satisfy SOX and PCI audit cycles, because monthly campaigns can help remove unused access, clean up orphaned accounts, and reduce standing privilege across service accounts, contractors, and policy exceptions. Security-led UARs turn a compliance process into a practical identity control.
Editorial analysis by NHI Mgmt Group, based on content published by C1.ai: “Beyond Checking the Box: How to Use UARs for Real Security”.
Key questions
Q: What breaks when access reviews are treated as a compliance exercise only?
A: You get sign-off without assurance.
Q: Why do unused accounts and service accounts create ongoing identity risk?
A: Unused and ownerless accounts often persist outside normal joiner-mover-leaver processes, so no one is clearly accountable for them.
Q: How can security teams tell whether UARs are reducing risk?
A: Look for evidence that reviews are removing access faster than new exceptions are created.
Practitioner guidance
- Target unused access with monthly campaigns Filter for users who have not logged in recently, especially in AWS and production environments, and revoke entitlements that no longer have an active business purpose.
- Map orphaned accounts to named owners Identify application accounts that do not map to a directory identity, then assign a responsible owner or remove the account before it becomes ungoverned access.
- Recertify service accounts on a recurring schedule Use recurring campaigns to have service account owners confirm purpose, configuration, and continued need, then remove or scope down access that is no longer justified.
Bottom line: User access reviews can do more than satisfy auditors, but only if they are designed to remove stale entitlements instead of merely documenting them.
What's in the full article
C1.ai's full blog post covers the operational detail this post intentionally leaves for the source:
- How to configure targeted UAR campaigns for unused access, orphaned accounts, service accounts, and contractor entitlements
- Examples of filtering logic for direct versus inherited access grants in policy enforcement
- Operational guidance for recurring review cadences and ownership assignment across service accounts
- How CEL can be used to automate approvals and revocations based on request metadata
👉 Read C1.ai's guidance on using user access reviews for real security →
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
UARs become a security control only when they are used to remove exposure between formal review cycles. A compliance-only programme proves that access was looked at, but it does not meaningfully change the amount of standing privilege that persists in the environment. The security value comes from using reviews to reduce stale entitlements faster than the business can accumulate them. Practitioners should treat cadence as a risk lever, not an audit calendar.
A question worth separating out:
Q: How should teams balance quarterly compliance reviews with ongoing access governance?
A: Use quarterly reviews for audit proof, but reserve recurring targeted campaigns for the access paths that change most often. That usually means production access, contractor entitlements, service accounts, and accounts with no recent use. The right model is layered: broad governance for assurance, narrower campaigns for actual risk reduction.
👉 Read our full editorial: UARs as a security control: what identity teams should change