A free user access review template you can fill in today

One sheet per system, one row per account, and a header that proves nothing was left out. Copy it free and run your first review this week.

This user access review template is free to copy. It fits one system per sheet. A header says where the account list came from and how many rows it had. Below it, each account gets a decision (keep, reduce or remove), a reason, and the ticket that made the change.

You need a spreadsheet, one export, and about an afternoon. No tool, no consultant, no email gate.

What this costs to run yourself

Almost nothing in money. The real cost is attention: someone has to pull the export, sit with a reviewer, and chase the removals to the end. That is an afternoon per system each cycle for a team of ten. The expensive version is the review that never happened. An examiner samples it, finds a gap, and the gap prints in the report your buyer reads.

So spend your effort on the three things that make a review count: a complete account list, a reviewer who is not the grantor, and a written decision on every row. The layout below is built around those three.

Part one: the header

Fill these six fields before touching a single row. They answer the first question any reader asks, which is whether the list in front of the reviewer was the whole list.

FieldWhat to write
SystemOne application or cloud account, spelled the way your asset list spells it
Dates coveredFirst and last day of the cycle
Where the list came fromReport name, tool, and the exact time it was run
Rows in the exportA number, so a missing account shows up as a mismatch
ReviewerA person and a job title. A team name does not count
Finished and approvedThe date the last row was decided and who accepted the result

Part two: one row per account

Eleven columns. The right hand column tells you what a bad entry looks like, because a cell can be full and still useless. Check each row against it before you sign.

ColumnFill it withA bad entry
Account IDThe login exactly as the export prints itA first name, which collides with the next Sam
Person, statusEmployee, contractor, leaver or service accountLeft empty, so nobody knows which rule applies
Role heldThe system’s own role name“Standard”, which decides nothing
Privileged?Yes or no, per your policy’s definitionNo on every row, including the admins
Granted when, by whomA date and an approverBlank. Write “unknown” if it is unknown
Why they have itThe work this access supports“Needs it”, which fits every row
DecisionKeep, reduce or removeA tick mark
Why that decisionRequired for reduce, remove and privileged keepEmpty next to a removal
TicketThe ID of the change request“Done”
Change landedWhen the access actually wentThe date the ticket was closed instead
Checked byA second person and the log they readThe reviewer again

A sample row, filled in

Here is one account as it would sit in the sheet. The contractor finished in spring. The admin role did not go with them, because offboarding closed the identity account and missed a group in the cloud console.

ColumnEntry
Headergcp-prod-billing, 2026-04-01 to 2026-06-30. IAM policy export run 2026-07-06 14:02 UTC, 29 rows. Reviewer: Lena Ortiz, Head of Engineering
Account IDj.whitfield@example.dev
Person, statusJo Whitfield, contractor, contract ended 2026-04-18
Role heldroles/owner through the eng-contractors group
Privileged?Yes
Granted when, by whom2025-12-02, Lena Ortiz, CHG-1180
Why they have itBilling data migration, finished 2026-04-18
DecisionRemove
Why that decisionContract over for 79 days. Group membership was outside the offboarding steps
TicketSEC-207, opened 2026-07-06
Change landed2026-07-06, 15:40 UTC
Checked byTomas Reyes, from the admin activity log entry for the group change

Keep this row. Quietly fixing the account and filing a clean sheet throws away proof that the control works. A year of reviews that never remove anyone looks less believable, not more.

Four rules the record has to follow

The template is the easy part. These rules decide whether the finished sheet holds up when somebody outside the company reads it a year from now.

The list comes out of the system
Run a named report and save it untouched next to the sheet. If the export has 29 rows and the sheet has 26, those three are what the review is for. The evidence request list asks for whole populations in the same way.
Someone else decides
An admin checking their own grants repeats a judgment already made.1 On a team of five that someone may be a founder, which is fine if the two names differ. SOC 2 on a small team covers the other places headcount forces that swap.
Every row gets words
A blank means it was not reviewed. A quarter with no changes is still written up: state the row count and that every account was kept.
Odd accounts get extra fields
A leaver found in the export gets their end date, the removal date and the gap in days. A service account gets a human owner, a last rotated date and a last used date. A shared login lists every holder and says whether the system can tell them apart.

What to keep once it is signed

Five files, created in this order and left alone afterwards. A sheet edited months after sign off raises a question the file itself cannot answer, so lock it or export a copy.

  1. The raw export, with the tool and run time visible.
  2. The finished sheet, every row decided, reviewer named, dated.
  3. A ticket for every change, cited by ID from its row.
  4. A log entry for every change, showing the access went.
  5. A dated approval, given after the last row was decided.

Where it maps in SOC 2

The review answers the logical access criteria.1 CC6.1 is about protecting the system with access controls. CC6.2 covers registering users before they get credentials and removing them when access stops being right. CC6.3 covers role based grants, changes and removals with least privilege in mind. Your auditor sets the exact mapping, and your own policy sets the pace you are tested on.2 How many policies you need explains how a copied promise turns into an exception, and five common control failures shows where access sits among them.

Keep it free, or let the software carry it

The template stays free, and running it by hand is a real option. If you would rather not chase exports every quarter, the cybersoftware software generates the review record, tracks each cycle and keeps the files with their dates, at $199 a month, cancel any time. Start with the free readiness assessment to see where access sits among your other gaps, or compare plans on pricing. It is priced for teams with no security hire.

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.

Questions

What is a user access review?
It is a scheduled look at every account that can reach one system. A person who did not grant the access decides, for each account, whether to keep it, cut it back or remove it, and writes down why. The removals it triggers are part of the same record.
What should the template contain?
A header naming the system, the dates covered, the export the account list came from, when that export was run, how many rows it had and who reviewed it. Under that, one row per account with the identifier, the person and their status, the role held, whether it is privileged, when and by whom it was granted, the reason for it, the decision, the reason for the decision, the ticket, the date the change landed and who checked it.
Who is allowed to review access?
Anyone except the person who granted or holds it. A manager who knows what the job needs is a better choice than the administrator who set the account up. At a very small company a founder can do it, as long as the record names two different people.
Is quarterly required, or can the review be annual?
Either can pass. Your policy picks the interval and the examination holds you to it. Promising quarterly and delivering twice a year creates an exception that an annual promise would have avoided, so write down the pace you will actually keep.
Do I need software to run access reviews?
No. A spreadsheet and a system export are enough, and the template on this page is free. Software helps with the part that slips, which is doing it on schedule and keeping every export, ticket and sign off together with dates intact.

Sources

  1. TSP Section 100, Trust Services Criteria for Security, Availability, Processing Integrity, Confidentiality, and Privacy AICPA. The criteria themselves, including the common criteria every SOC 2 report covers. Checked 1 August 2026.
  2. Statements on Standards for Attestation Engagements AICPA. The attestation standards a SOC 2 examination is performed under. Checked 1 August 2026.

Get audit-ready without a compliance team

The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.

Start with a free readiness assessment

cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.