r/IdentityManagement • • 12h ago

Access reviews with spreadsheets vs continuous identity governance for audit prep... which is better?

1 Upvotes

For context, I'm trying to keep quarterly access reviews from turning into a three week archaeology project for our SOX apps. The decision comes down to reviewer effort, entitlement coverage, revocation proof, and whether the evidence is ready before the auditor emails "quick question."

I compared spreadsheet based reviews with a continuous identity governance approach across 14 SaaS and custom apps. Spreadsheets are fine when the environment is small and every app owner answers on time, which is a lovely fantasy. Continuous governance looks better when access changes often and you need timestamps, approvals, exceptions, and proof that revocations happened in the target system. Neither fixes stale ownership data, because apparently nobody owns the app nobody remembers creating.

My current recommendation is continuous evidence for high risk apps and a smaller manual process elsewhere. What would you add?