SOC 2 Wants Proof. Not a Spreadsheet.
Most access reviews are a formality. Managers approve without context, shadow IT goes unreviewed, and evidence is thin. Here is what SOC 2 and ISO 27001 actually require, and what closing the gap looks like.
Short answer
Software that automates user access reviews for SOC 2 has to do five things: collect who has access to what across every SaaS tool, assign each line to a reviewer, record a keep-or-remove decision, execute the removals, and export the evidence in a form an auditor accepts. Lutril's access review campaigns do all five. The Access Grid is the inventory, reviewers decide in Slack, Teams or the app UI, removals execute automatically, and the evidence is one link showing who reviewed what, when, and proof the revocation happened, mapped to SOC 2 CC6.1 to CC6.3 and ISO 27001 A.5.18.
Your access review works on paper
Every quarter, someone on the security team sends a spreadsheet to 40 managers. The managers are busy, uncertain about what their reports actually use, and unclear on what "review" really means. They click approved on most rows and send it back. Someone collects the responses. The audit evidence folder gets another attachment.
This is how most companies do access reviews today. It satisfies the letter of the requirement. It increasingly doesn't satisfy auditors, and it definitely doesn't satisfy the spirit of what SOC 2 and ISO 27001 are asking for.
What the standards actually require
Both SOC 2 and ISO 27001 care about the same fundamental question: can you prove that access is controlled, appropriate, and cleaned up when it shouldn't be there anymore?
The key distinction for SOC 2 is between Type I and Type II. Type I says: "we have controls designed to achieve these criteria." Type II says: "those controls operated effectively over the audit period." For access reviews, Type II means demonstrating that reviews happened, were complete, and resulted in removals, consistently over 6–12 months.
"We have a policy" is a Type I answer to a Type II question.
Three ways access reviews fail in practice
What good evidence looks like
What auditors want to see is a closed loop: discovery → review → decision → remediation → evidence. Each step traceable, timestamped, and attributable to a named reviewer.
Here's what a structured review campaign looks like when the data is actually there to support it:
The "last active" column is what makes the difference between a real review and a rubber stamp. Without it, a manager reviewing Tom's access has no basis for a decision. With it, "94 days ago" on a Salesforce admin account is an obvious flag.
For audit purposes, the export from this review needs to show:
The frequency question
SOC 2 doesn't prescribe a specific review cadence, but most auditors expect quarterly reviews for privileged access and at least annual for standard users. ISO 27001 says "at regular intervals", typically interpreted as quarterly or semi-annual depending on your risk profile.
The more useful question is: why is frequency the constraint?
The quarterly cadence is an artifact of the manual process. Collecting access data, building spreadsheets, chasing manager responses, reconciling removals. It takes long enough that doing it more often isn't realistic. But the underlying risk is continuous. Someone changes roles on a Tuesday in February. The next review isn't until April. For two months, they have access they shouldn't.
When access data is live and review campaigns are automated, reviews can be triggered by events: a role change, a project closing, 60 days of inactivity, rather than just the calendar. The quarterly review becomes a compliance artifact that confirms what continuous monitoring already caught, rather than a first line of discovery.
That's the difference between access review as a compliance exercise and access review as an actual control.
Questions that follow
What software automates user access reviews for SOC 2 compliance?
Access governance platforms that connect to each SaaS tool, build the who-has-what inventory, run review campaigns with reviewers and decisions, execute the removals, and export evidence. Lutril does this for SaaS tools and AI agents in one campaign, with decisions taken in Slack, Teams or the app UI.
How often do SOC 2 and ISO 27001 require access reviews?
Neither standard fixes a number. SOC 2 CC6.1 to CC6.3 and ISO 27001 A.5.18 require that access rights are reviewed at regular intervals and on role change or departure, and that the review is evidenced. Quarterly for privileged access and at least annually for everything else is what most auditors accept.
What evidence does an auditor want from an access review?
The scope (which systems, which accounts), who reviewed each line, the decision, the date, and proof that removals actually happened in the target system. A spreadsheet with ticks fails the last point. Lutril's campaign export carries the revocation log alongside the decisions.
Do AI agents need to be in the access review?
Yes. An agent holds credentials and permissions like any account. Lutril includes registered agents in the same campaign as employees, so an idle or over-scoped agent gets the same keep-or-remove decision, and the decision executes.
In thirty minutes we map Lutril to your stack and show what real-time access governance looks like for your team. No slides.
Book a Demo