Back to Explore
🔐

Technology

Access Rights Recertification

Status of periodic user access reviews and the volume of excessive or stale entitlements found.

📖 6 min read🎯 Intermediate✍️ Updated 2026

Why stale access is a standing control failure

Excessive and stale user entitlements are among the most common IT control weaknesses the AGSA reports, and they directly undermine segregation of duties and POPIA obligations to limit data access. Periodic recertification, where owners confirm that each user still needs their access, is the control that keeps entitlement creep in check. AuditPro Core tracks recertification status and the volume of excessive or stale rights uncovered.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

Reviews due

62

Completed

48

77%

Excess entitlements

214

to revoke

Dormant accounts

89

▲ 22

Flagged entitlements by system

Recertification by system

SystemUsersReviewed %Revoked
Financial (BAS)4208241
Payroll (PERSAL)967128
SCM portal1887922
HR system1456817
Active Directory6107433

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

Access recertification

Recertification is a periodic review where the appropriate owner confirms or revokes each user's access. It counters the natural drift of accumulating rights over time.

Excessive entitlements

An excessive entitlement is access beyond what a role requires, often breaking segregation of duties. It widens both the fraud surface and the data-breach surface.

Stale access

Stale access belongs to leavers, movers or dormant accounts that retain rights they no longer need. It is a frequent route for unauthorised or untraceable activity.

Review completeness

A recertification campaign is only as good as its completion rate. Unreviewed populations leave blind spots that defeat the purpose of the control.

How AuditPro Core Bridges the Gap

  • Campaign tracking: recertification status is monitored per system and per reviewer to completion.
  • Exception flagging: excessive and stale entitlements are surfaced for revocation through a workflow.
  • Continuous monitoring: the platform watches for entitlement drift between formal review cycles.
  • Audit-ready export: completed recertifications and revocations export as evidence for IT general control audits.

Key Takeaways

  • Entitlement creep erodes segregation of duties and POPIA data limits.
  • Stale leaver and dormant accounts are a common unauthorised-access route.
  • Recertification only works at high completion; unreviewed populations are blind spots.
  • Track both review status and the volume of rights actually revoked.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.