---
id: KB-ET-010
url: https://app.codecontract.io/help/your-workspace/reviewing-permissions-once-a-year
idioma: en
categoria: espacio-de-trabajo
subcategoria: usuarios
audiencia: administrador
nivel: avanzado
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-ET-005, KB-AD-003]
citadoPor: [KB-ET-013, KB-AD-014]
---

# The annual permission review

_Half an hour that prevents the problem nobody sees coming._

**Responde a:** review who has access to what · internal permission audit · clean up old accesses · someone has more permissions than they need

Permissions do not break suddenly: they accumulate. Someone changes role and keeps the old access, someone gets "temporary" access to a project and nobody removes it, an external auditor comes in and is still there two years later. None of that announces itself.

## The four questions

1. **Is everyone on this list still here?** — It is what comes up most, and the easiest to fix.
2. **Did anyone change role and keep the old access?** — A promotion leaves permissions that no longer match what they do.
3. **How many administrators are there?** — It should be two. If it is seven, nobody feels responsible for anything.
4. **Any external access still open?** — Accountants, auditors, one-off collaborators. They are the most forgotten because nobody misses them.

## What usually turns up

| Finding | Frequency | What to do |
| --- | --- | --- |
| Accounts of people who left | Nearly always | Close them that day |
| Permissions inherited from a previous role | Very common | Adjust to what they do now |
| Too many administrators | Common | Reduce to two |
| An external with months-old access | Common | Remove it; if needed again, grant it again |

> [!IMPORTANT]
> Removing a permission is not distrust, and it is worth saying so when you do it. Surplus access is a risk to that person too: if their account is compromised, what the intruder takes is everything they could see.

> [!WARNING]
> Do not run the review on a Friday afternoon. If you remove something by mistake, someone cannot work and nobody can fix it until Monday.

> [!NOTE]
> Half an hour a year. Against the cost of discovering during an audit that six accounts of departed staff are still open, it is the best effort-to-result ratio in the whole of administration.

**Should people be told?**

If it affects what they do, yes, and one sentence suffices.

**Is the change recorded?**

Yes, who made it and when.

**Can I see who has never signed in?**

The log shows it, and it is usually the first place to look.

## Ejemplos

**A company runs its first permission review after two years.**

- Closes six accounts of people who left
- Reduces administrators from nine to two
- Removes access granted for an audit eighteen months ago

→ Half an hour closes nine open doors nobody knew were there.

**Nobody has reviewed permissions in years.**

- Schedules the annual review

→ Access reflects today's organisation.

**People leave and their access stays active.**

- Cross-checks the user list with joiners and leavers

→ The active accounts are the right ones.

**There are permissions nobody remembers granting.**

- Reviews case by case with the owner

→ What remains has a reason.

**The review happens and nothing is recorded.**

- Records what was reviewed and what changed

→ The review is demonstrable.

**An auditor asks about access control.**

- Shows the review with its date

→ The control moves from assertion to evidence.
