A free user access review template you can fill in today
One sheet per system, one row per account, and a header that proves nothing was left out. Copy it free and run your first review this week.
This user access review template is free to copy. It fits one system per sheet. A header says where the account list came from and how many rows it had. Below it, each account gets a decision (keep, reduce or remove), a reason, and the ticket that made the change.
You need a spreadsheet, one export, and about an afternoon. No tool, no consultant, no email gate.
What this costs to run yourself
Almost nothing in money. The real cost is attention: someone has to pull the export, sit with a reviewer, and chase the removals to the end. That is an afternoon per system each cycle for a team of ten. The expensive version is the review that never happened. An examiner samples it, finds a gap, and the gap prints in the report your buyer reads.
So spend your effort on the three things that make a review count: a complete account list, a reviewer who is not the grantor, and a written decision on every row. The layout below is built around those three.
Part one: the header
Fill these six fields before touching a single row. They answer the first question any reader asks, which is whether the list in front of the reviewer was the whole list.
| Field | What to write |
|---|---|
| System | One application or cloud account, spelled the way your asset list spells it |
| Dates covered | First and last day of the cycle |
| Where the list came from | Report name, tool, and the exact time it was run |
| Rows in the export | A number, so a missing account shows up as a mismatch |
| Reviewer | A person and a job title. A team name does not count |
| Finished and approved | The date the last row was decided and who accepted the result |
Part two: one row per account
Eleven columns. The right hand column tells you what a bad entry looks like, because a cell can be full and still useless. Check each row against it before you sign.
| Column | Fill it with | A bad entry |
|---|---|---|
| Account ID | The login exactly as the export prints it | A first name, which collides with the next Sam |
| Person, status | Employee, contractor, leaver or service account | Left empty, so nobody knows which rule applies |
| Role held | The system’s own role name | “Standard”, which decides nothing |
| Privileged? | Yes or no, per your policy’s definition | No on every row, including the admins |
| Granted when, by whom | A date and an approver | Blank. Write “unknown” if it is unknown |
| Why they have it | The work this access supports | “Needs it”, which fits every row |
| Decision | Keep, reduce or remove | A tick mark |
| Why that decision | Required for reduce, remove and privileged keep | Empty next to a removal |
| Ticket | The ID of the change request | “Done” |
| Change landed | When the access actually went | The date the ticket was closed instead |
| Checked by | A second person and the log they read | The reviewer again |
A sample row, filled in
Here is one account as it would sit in the sheet. The contractor finished in spring. The admin role did not go with them, because offboarding closed the identity account and missed a group in the cloud console.
| Column | Entry |
|---|---|
| Header | gcp-prod-billing, 2026-04-01 to 2026-06-30. IAM policy export run 2026-07-06 14:02 UTC, 29 rows. Reviewer: Lena Ortiz, Head of Engineering |
| Account ID | j.whitfield@example.dev |
| Person, status | Jo Whitfield, contractor, contract ended 2026-04-18 |
| Role held | roles/owner through the eng-contractors group |
| Privileged? | Yes |
| Granted when, by whom | 2025-12-02, Lena Ortiz, CHG-1180 |
| Why they have it | Billing data migration, finished 2026-04-18 |
| Decision | Remove |
| Why that decision | Contract over for 79 days. Group membership was outside the offboarding steps |
| Ticket | SEC-207, opened 2026-07-06 |
| Change landed | 2026-07-06, 15:40 UTC |
| Checked by | Tomas Reyes, from the admin activity log entry for the group change |
Keep this row. Quietly fixing the account and filing a clean sheet throws away proof that the control works. A year of reviews that never remove anyone looks less believable, not more.
Four rules the record has to follow
The template is the easy part. These rules decide whether the finished sheet holds up when somebody outside the company reads it a year from now.
- The list comes out of the system
- Run a named report and save it untouched next to the sheet. If the export has 29 rows and the sheet has 26, those three are what the review is for. The evidence request list asks for whole populations in the same way.
- Someone else decides
- An admin checking their own grants repeats a judgment already made.1 On a team of five that someone may be a founder, which is fine if the two names differ. SOC 2 on a small team covers the other places headcount forces that swap.
- Every row gets words
- A blank means it was not reviewed. A quarter with no changes is still written up: state the row count and that every account was kept.
- Odd accounts get extra fields
- A leaver found in the export gets their end date, the removal date and the gap in days. A service account gets a human owner, a last rotated date and a last used date. A shared login lists every holder and says whether the system can tell them apart.
What to keep once it is signed
Five files, created in this order and left alone afterwards. A sheet edited months after sign off raises a question the file itself cannot answer, so lock it or export a copy.
- The raw export, with the tool and run time visible.
- The finished sheet, every row decided, reviewer named, dated.
- A ticket for every change, cited by ID from its row.
- A log entry for every change, showing the access went.
- A dated approval, given after the last row was decided.
Where it maps in SOC 2
The review answers the logical access criteria.1 CC6.1 is about protecting the system with access controls. CC6.2 covers registering users before they get credentials and removing them when access stops being right. CC6.3 covers role based grants, changes and removals with least privilege in mind. Your auditor sets the exact mapping, and your own policy sets the pace you are tested on.2 How many policies you need explains how a copied promise turns into an exception, and five common control failures shows where access sits among them.
Keep it free, or let the software carry it
The template stays free, and running it by hand is a real option. If you would rather not chase exports every quarter, the cybersoftware software generates the review record, tracks each cycle and keeps the files with their dates, at $199 a month, cancel any time. Start with the free readiness assessment to see where access sits among your other gaps, or compare plans on pricing. It is priced for teams with no security hire.
cybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.
Questions
What is a user access review?
What should the template contain?
Who is allowed to review access?
Is quarterly required, or can the review be annual?
Do I need software to run access reviews?
Sources
Get audit-ready without a compliance team
The readiness assessment is free, with no payment and no card. When you are ready, the software is $199 a month, cancel any time, and audits go through our preferred pricing program. You can be audit-ready starting at about a week.
Start with a free readiness assessmentcybersoftware is not a CPA firm. SOC 2 examinations are performed by independent licensed U.S. CPA firms.