2026-10-02
Blog6 min readGRCAccess Reviews That Are Not Theater: How Small SaaS Teams Prove Least Privilege
For a lot of small SaaS teams, the access review exists as a ritual, not as an operating habit.
Once a year someone exports a user list from the identity provider, pastes it into a spreadsheet, and asks managers to “confirm” access they barely remember granting. Screenshots get filed. Orphaned admin accounts stay quiet in production. Privilege creep grows because the review never changes how access is granted, changed, or removed. That is theater. Buyers notice. Later, so do auditors. Proving least privilege does not require a monthly fire drill. It requires a light cadence: clear scope, named owners, reusable evidence, and honest exceptions.
What theater looks like
Theater is easy to spot from the inside.
The annual spreadsheet. Access is “reviewed” once, usually under deal pressure or before a hoped for formal examination. Rows are marked approved in bulk. Nobody can say which systems were in scope, which roles matter, or what changed since the last pass.
Rubber stamp screenshots. A portal export or a console capture stands in for a decision. There is no recorded rationale, no manager who actually owns the risk, and no follow up when something looks wrong. The artifact exists to fill a folder, not to change entitlements.
Orphaned admin accounts. Former contractors still hold production roles. Shared break glass users have no owner. Service accounts created for a migration never got retired. The review either skipped non human identities or treated them as someone else’s problem.
Privilege creep as normal. New tools join SSO with broad default groups. Temporary elevated access becomes permanent. Managers approve “same as last quarter” without checking whether someone still needs admin on billing, support, or the data warehouse.
The failure mode is a control story you cannot defend: you claim least privilege, but your evidence shows annual ceremony and stale admins.
Why buyers and later auditors care about least privilege proof
Enterprise and mid market buyers ask access questions early, often inside the same security questionnaires that stall deals. They want to know who can reach customer data, how admin rights are granted, how often access is reviewed, and what happens when someone leaves. Those answers are diligence now. They are not waiting for your formal examination period.
Least privilege is also one of the control themes that shows up again when you pursue a formal attestation. Independent firms look for operating evidence that matches the examination they perform: who reviewed what, on which date, for which systems, with which outcomes. A single screenshot from last December does not carry that story. A repeatable cadence with owners and retained artifacts does.
For SaaS and fintech teams between about 10 and 200 people, the gap is usually process, not intent. You care about locking down production. What you lack is a way to prove it without burning a week every month. Buyers discount fiction. Auditors will too. Current access review evidence keeps both conversations grounded.
A light operating cadence for 10 to 200 person SaaS
Good access review ops are boring on purpose. Aim for a rhythm your team can keep, not a perfect framework you drop after one quarter.
Scope. Name the systems that matter: identity provider, cloud console, production app admin, source control, customer support tooling, billing, and any store of customer data. Include non human identities where they hold real power. Leave low risk marketing tools aside until the core is stable.
Owners. Every in scope system has a human accountable for the review outcome, not a shared inbox. Managers attest to their people’s access. A GRC owner (internal or external) runs the calendar, tracks exceptions, and keeps evidence findable. Engineering owns production role design. Ops or IT owns joiner, mover, and leaver mechanics.
Cadence. Quarterly is enough for many 10 to 200 person teams if the scope is real and exceptions get closed. High risk admin roles may need a tighter loop. The point is a date on the calendar with a done definition, not a vague “we review access regularly” line in a policy.
Evidence. Keep a short record each cycle: systems in scope, population source (for example an IdP export), reviewers, date, decisions (retain, change, revoke), and follow on tickets. Store it where the next questionnaire or readiness push can find it. GRC platforms help; a clean folder and ticket trail can work while you grow.
Exceptions. Orphaned admins, unknown service accounts, and “temporary” privileges that never expired are the point of the exercise. Log them, assign an owner, set a close date, and follow through. A review that finds nothing forever is usually a review that is not looking.
Joiner, mover, leaver hooks. The cadence fails if access changes only during the quarterly pass. Tie hire, role change, and offboarding to the same owners so the periodic review is confirmation, not archaeology.
None of this requires pretending you already hold an attestation. It is least privilege as GRC delivery work.
How this feeds questionnaires and later audit readiness (without overclaiming)
When a buyer asks how often you review access, you should be able to point at the last cycle: scope, owners, evidence, open exceptions. That is questionnaire readiness in plain terms. The same claim to control to artifact map that helps with vendor packets also reduces scramble when an independent assessor asks for operating evidence later.
What this is not:
- It is not a SOC 2 Type I or Type II report.
- It is not “certified,” “attested,” or “audited” by Grey Wing.
- It is not a substitute for a licensed firm’s opinion.
Teams that run this cadence usually do it with whoever owns GRC day to day, inside or outside. The job is the operating work: calendar, owners, evidence, exception follow through. That is readiness help. It is not an auditor's opinion, and it is not a certificate. When a formal examination starts, the independent firm still owns the report. Good prep just means you are not inventing the story under deadline.
Keeping that line clear protects sales conversations and any attestation you eventually pursue.
Practical next steps
If your last access review felt like theater, run this in the next month:
- List in scope systems. Start with identity, cloud admin, production app admin, source control, and anywhere customer data is reachable.
- Pull a current population. Export users and admin roles from the source of truth; include service accounts you can see.
- Name reviewers. One accountable owner per system; managers for people access; a single person accountable for closing the cycle.
- Define done. Every row gets retain, change, or revoke, with tickets for changes; exceptions get owners and due dates.
- File the evidence pack. Scope, export, decisions, tickets, exception list, dated and findable.
- Separate the backlog. Access review ops this quarter; formal audit readiness as a deliberate program when timing and buyers require it, not as a rename of the annual spreadsheet.
If you want help standing that cadence up, or you have an admin list nobody trusts, contact Grey Wing. Bring the last review that felt like theater. We will talk through ownership of the GRC work, not promises about certificates we do not issue.