Run user access reviews as campaigns, not a once-a-year spreadsheet. TATER finds the orphaned accounts, gives you a decision that never permanently approves the awkward ones, dispositions each removal to the right offboarding steps, and exports the full decision trail for your auditor.
Most access reviews stall because the data is stale and the decisions go nowhere. TATER pulls live Entra membership, surfaces the accounts nobody owns, and turns every decision into a tracked action with an audit trail — so the campaign actually reaches done.
A one-click scan diffs every Entra member account against your People directory (the active-employee roster) and surfaces accounts with no matching employee — flagged no-matching-employee plus disabled, dormant, or never-signed-in, with last-sign-in context. No-op if the roster is empty, so it never false-flags everyone.
For access that is legitimately retained but must never be permanently approved — a shared mailbox, a departed exec’s inbox — a “Keep + recheck” decision keeps it now but re-surfaces it as pending in every future cycle, carrying the prior decision and justification forward as read-only context. No permanent snooze.
Revoking access dispositions the item to an offboarding profile that matches the account type — Intern/Contractor (delete), Departing Employee (disable + strip groups, retain mailbox), Manager/Exec (convert to shared mailbox), Service/Shared (assign owner or decommission). The correct steps ride onto the remediation task at finalize.
One button downloads a CSV of the per-item decision trail — account, access, decision, decision-maker, timestamp, justification, and the resulting Ops ticket — plus the campaign’s mapped control-evidence, so a SOC auditor can sample decisions and attach the supporting rationale.
The campaign runs the whole certification, and every removal turns into a real offboarding action instead of a note.
Pull live access into review items and run the orphaned-account scan so nothing un-owned slips through.
Keep, keep-and-recheck, or revoke each item — revocations pick the account-type offboarding profile.
Finalizing generates the remediation tasks and locks the decision trail, ready to export for the auditor.
The quarterly access review is due and half the accounts belong to people who left months ago.
The orphaned-account scan surfaces every account with no active employee behind it, with last-sign-in context — so the cleanup list writes itself instead of being reconstructed by hand.
A departed exec’s mailbox has to stay live for continuity, but it keeps getting rubber-stamped “approved” every cycle.
Keep-and-recheck retains it now but forces a fresh confirmation next cycle, with the prior rationale in view — no account quietly becomes permanent.
“Show me who reviewed this access, what they decided, and why.”
The decision-trail CSV carries the reviewer, decision, timestamp, justification, and resulting ticket per item — a sample-and-attach exercise, not an archaeology project.
The guide covers launching a campaign, running the orphaned-account scan, choosing offboarding profiles, and exporting the decision trail.
See campaigns, orphaned-account detection, and the auditor export on your own tenant in a live walkthrough.