🔍 OasisPro · IFS Cloud Access Review · Governance · PermissionWorks
IFS Cloud access review,
6 essential steps to get right.
IFS Cloud access review exercises exist at most organisations in some form, and a surprising number of them check the wrong thing. Confirming that every account belongs to a current employee is necessary and nowhere near sufficient. The real question a review needs to answer is whether each person's access still matches the role they hold today, and that question requires comparing access against roles, not just against a headcount list.
Done properly, a review is what catches the drift that accumulates silently between moves, promotions and one-off exceptions.
Here are the 6 steps that make it worth doing.
The most common access review failure is not skipping the review. It is running one that only asks whether an account is active, when the real risk lives in whether that account's access still matches the job the person actually does.
An account belonging to a current, employed person will pass almost every superficial check. It can still carry permissions from a role they left eighteen months ago, stacked on top of what their current role genuinely needs. That gap is invisible to a review that stops at "is this person still here" and completely visible to a review that asks "does this match their current role."
The 6 steps of an IFS Cloud access review that works
- 1. Compare access to defined roles, not to a headcount list. The question is not whether the account exists. It is whether the permission sets assigned match what the person's current role actually requires.
- 2. Sample real usage, not just assigned permissions. A permission that is granted but never used for a year is a different risk to one used daily, and both are worth flagging differently.
- 3. Check movers as a specific category. Internal moves are where drift accumulates fastest, because old access is rarely removed automatically. Pull a sample of recent movers and check explicitly whether their previous role's access was actually withdrawn.
- 4. Get sign-off from someone who understands the job. A line manager or process owner can say whether access is appropriate. IT can confirm what is technically assigned, but rarely has the context to judge whether it should be.
- 5. Record the evidence, not just the outcome. Who reviewed what, when, and what they decided. A review with no audit trail is indistinguishable from a review that never happened, from an auditor's perspective.
- 6. Remediate findings, do not just report them. A review that produces a list of issues nobody acts on is worse than no review, because it demonstrates the organisation knew and did nothing.
What good evidence looks like
A dated record naming the reviewer, the scope reviewed, and the specific decision for each flagged item. Not a general statement that a review took place, but a traceable record an auditor can follow line by line.
Why movers need their own pass
A general review sampling the whole population will dilute the mover-specific risk across everyone else. Pulling movers as their own category surfaces the pattern that a blended sample tends to hide.
Annual is a floor, not a target
An annual review catches what accumulated over the year. Movers and leavers handled continuously as they happen is what actually keeps the exposure window short, with the annual review as the backstop.
Why a composable role model makes the review dramatically easier
If access is assigned through a small number of well-defined roles, reviewing it means checking whether each person's role assignment is current, a fast, structured exercise. If access has been assembled individually for each person over time, reviewing it means reconstructing what each person actually has before you can even ask whether it is right. The review is only as easy as the model behind it.
Making an IFS Cloud access review a routine, not a fire drill
A review that only happens under pressure, right before an audit visit, will always feel rushed and will always miss things a calmer process would catch.
Build the review calendar around your role model rather than around IT capacity, so the exercise genuinely happens on a fixed schedule rather than whenever someone finally has time for it.
Pull movers out as a named category every single time, since that one step alone catches the largest and most consistent source of findings across almost every review we run.
Track every remediation through to completion, not just to a logged finding, because an unresolved finding carried over from last year's review is genuinely worse evidence than no review having happened at all.
The UK's National Cyber Security Centre publishes genuinely useful general access control principles that apply directly to structuring a sensible review cadence.
The IFS documentation site covers the permission set mechanics a review actually checks, useful when confirming exactly what a flagged finding means.
Our segregation of duties guide covers the specific conflict evidence a review needs to produce for audit purposes.
A review that only checks accounts are active answers the wrong question. The right question is whether access still matches the job, and that takes comparing against roles, not against a headcount.
Common findings an IFS Cloud access review turns up
Access matching a role someone left months or years ago, almost always from an internal move rather than a leaver, and consistently the largest single category of finding.
Temporary access granted for a specific project or busy period, with no expiry date, still active long after the reason for it ended.
And occasionally, access nobody can explain at all, granted by a colleague who has since left, copied from a template that no longer matches anyone's actual job.
PermissionWorks makes the comparison the review actually needs.
Because permission sets are generated from documented role definitions, an access review becomes a direct comparison between what is assigned and what the role defines, rather than a manual reconstruction exercise. Findings come with the evidence trail already attached.
Build the role model a review depends onFind out what your next access review would actually find.
We will sample your current access against your defined roles, check your recent movers specifically, and show you what a properly evidenced review looks like before you run your next one.
How often should an IFS Cloud access review happen?
At least annually as a formal, documented exercise, with a lighter check after any significant restructure. Annual review alone is not sufficient control on its own, since movers and leavers should be handled continuously as they happen, but it is a necessary backstop for whatever the continuous process missed.
What is the difference between an access review and an access certification?
A review is the process of checking access against current roles. A certification is the formal record that a named person confirmed each user's access was appropriate at a point in time. Many organisations run the review but skip the certification step, which is exactly what leaves them unable to evidence the review happened when an auditor asks.
Who should actually sign off an IFS Cloud access review?
The line manager or process owner who genuinely knows what a role requires, not IT or a system administrator reviewing a list they cannot fully interpret. IT can run the mechanics of the review, but the judgement about whether access is still appropriate belongs with someone who understands the job.
What is the most common finding in a first IFS Cloud access review?
Access that matches a role the person no longer holds, usually from an internal move where the old permissions were never removed. This is consistently the largest single category of finding, ahead of leavers and ahead of one-off exceptions.
An IFS Cloud access review is only as good as what it compares against
Get that specific comparison right, and the whole yearly exercise stops feeling like a chore nobody genuinely wants to own.
Checking that accounts belong to current employees is table stakes. The review that actually protects the business compares access against current roles and catches movers specifically.
Evidence it properly, get sign-off from someone who understands the job, and remediate what you find rather than filing it.
That combination is what turns an annual exercise into a control that genuinely works.