TL;DR: Access reviews only become defensible when visibility, decision rights, and entity-level data isolation are separated by role, row, and configuration, according to Veza. That model matters because least privilege in IGA is now a compliance control, not just an administrative preference.
Editorial analysis by NHI Mgmt Group, based on content published by Veza: “Defining Access: Roles and Controls in Veza Access Reviews”.
Key questions
Q: How should teams separate reviewer access from review administration in IGA?
A: Teams should design access reviews with separate controls for who can administer campaigns and who can act on assigned rows.
Q: When should organisations use entity-level isolation for access reviews?
A: Organisations should use entity-level isolation whenever review evidence, approvals, or campaign data must stay separate across subsidiaries, business units, or regulated operating entities.
Q: Where do access review programmes most often lose least privilege?
A: They lose least privilege when reviewer visibility, operator administration, and audit oversight are collapsed into broad tenant permissions.
Practitioner guidance
- Separate action rights from visibility rights Design review permissions so campaign administration, reviewer decisions, monitoring, and audit certification are governed independently from review-data visibility.
- Scope reviewers to assigned rows only Ensure reviewers can only see the rows they are assigned and nothing else, even when they also hold an administrative persona elsewhere in the tenant.
- Apply Limit Access by operating entity Use configuration-level access controls to keep one entity's review campaigns, review configurations, and inherited reviews isolated from another's.
Bottom line: Access reviews only function as defensible controls when visibility and decision rights are separated by persona and by entity.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Granular access review control is now part of the compliance control plane. Access reviews are no longer just a workflow for certifying entitlements. They are an enforcement layer that produces evidence, which means permission design has to satisfy compliance requirements as tightly as the underlying access model.
A few things that frame the scale:
- Over 70% of organisations lack automated access risk analysis, user access reviews and provisioning and deprovisioning, according to Pathlock's 2025 Digital Transformation and Access Risk Report.
A question worth separating out:
Q: What should auditors look for in an access-request control?
A: They should look for a record that shows the requester, the approver, the business reason, the policy decision and the provisioning outcome in one place. If any of those elements are missing, the organisation is relying on evidence fragments rather than a control that can be independently reconstructed.
👉 Read our full editorial: Granular access review controls are becoming a compliance control plane