Feature · TATER Security · Identity

Access reviews that actually finish — with the trail auditors want.

Run user access reviews as campaigns, not a once-a-year spreadsheet. TATER finds the orphaned accounts, gives you a decision that never permanently approves the awkward ones, dispositions each removal to the right offboarding steps, and exports the full decision trail for your auditor.

See it in a walkthrough How it works
What it does

A review that gathers itself and closes itself out.

Most access reviews stall because the data is stale and the decisions go nowhere. TATER pulls live Entra membership, surfaces the accounts nobody owns, and turns every decision into a tracked action with an audit trail — so the campaign actually reaches done.

Orphaned-account detection

A one-click scan diffs every Entra member account against your People directory (the active-employee roster) and surfaces accounts with no matching employee — flagged no-matching-employee plus disabled, dormant, or never-signed-in, with last-sign-in context. No-op if the roster is empty, so it never false-flags everyone.

Keep & always re-review

For access that is legitimately retained but must never be permanently approved — a shared mailbox, a departed exec’s inbox — a “Keep + recheck” decision keeps it now but re-surfaces it as pending in every future cycle, carrying the prior decision and justification forward as read-only context. No permanent snooze.

Account-type end-state profiles

Revoking access dispositions the item to an offboarding profile that matches the account type — Intern/Contractor (delete), Departing Employee (disable + strip groups, retain mailbox), Manager/Exec (convert to shared mailbox), Service/Shared (assign owner or decommission). The correct steps ride onto the remediation task at finalize.

Auditor decision-trail export

One button downloads a CSV of the per-item decision trail — account, access, decision, decision-maker, timestamp, justification, and the resulting Ops ticket — plus the campaign’s mapped control-evidence, so a SOC auditor can sample decisions and attach the supporting rationale.

How it works

Collect, decide, finalize.

The campaign runs the whole certification, and every removal turns into a real offboarding action instead of a note.

Collect

Pull live access into review items and run the orphaned-account scan so nothing un-owned slips through.

Decide

Keep, keep-and-recheck, or revoke each item — revocations pick the account-type offboarding profile.

Finalize

Finalizing generates the remediation tasks and locks the decision trail, ready to export for the auditor.

In practice

Three access reviews this turns around.

The IT admin, quarter close

The quarterly access review is due and half the accounts belong to people who left months ago.

The orphaned-account scan surfaces every account with no active employee behind it, with last-sign-in context — so the cleanup list writes itself instead of being reconstructed by hand.

The security lead

A departed exec’s mailbox has to stay live for continuity, but it keeps getting rubber-stamped “approved” every cycle.

Keep-and-recheck retains it now but forces a fresh confirmation next cycle, with the prior rationale in view — no account quietly becomes permanent.

The auditor, evidence pull

“Show me who reviewed this access, what they decided, and why.”

The decision-trail CSV carries the reviewer, decision, timestamp, justification, and resulting ticket per item — a sample-and-attach exercise, not an archaeology project.

Ready to set it up?

The guide covers launching a campaign, running the orphaned-account scan, choosing offboarding profiles, and exporting the decision trail.

Access reviews guide  →

Make your next access review the one that finishes.

See campaigns, orphaned-account detection, and the auditor export on your own tenant in a live walkthrough.

Book a walkthrough All features