AI access review agent: Run access reviews from real entitlement data, not last quarter's spreadsheet

Category: Security & Compliance

ZeroTwo pulls exported entitlement lists and role baselines from approved folders, checks ticket history for the access that was actually requested, and sends every proposed revocation to Slack for an owner decision before anything changes.

Integrations: google_drive, atlassian, slack

What Changes

DimensionBeforeWith ZeroTwo
Gathering entitlementsSomeone exports each system by hand and pastes the results into a review workbookExports and the documented baseline are read from one approved folder
Deciding what looks wrongReviewers scan thousands of rows and approve in bulk once fatigue sets inFindings are grouped by reason, with the export row and request ticket attached
Justifying accessNobody remembers why a permission was granted two reorganisations agoEach entitlement is matched to its request ticket, or explicitly marked unexplained
Evidence for auditorsSign-off lives in an email thread and a workbook tab that gets overwrittenReviewer, decision, timestamp, and source data are saved together per cycle

Why teams use ZeroTwo for access reviews

Access reviews fail quietly when the data is assembled by hand

Quarterly access review arrives, someone exports entitlements from a handful of systems, pastes them into a workbook, and sends tabs to managers who have no context for what a permission actually grants. The rows that get read carefully are the first few dozen. The rest get approved because the deadline is real and the detail is not legible.

The reason this decays is not laziness. It is that the useful context lives somewhere other than the export. Why an engineer holds production database access is in an old ticket. Whether a permission exceeds the role baseline requires the baseline document. Whether an account belongs to someone who left requires the leaver list. A review that cannot reach those sources can only ask reviewers to remember, and memory is what the control exists to replace.

How ZeroTwo prepares an access review cycle

  1. Collects entitlement exports and role baselines — ZeroTwo reads the approved folder holding this cycle's entitlement exports, the documented role-to-permission baseline, the current joiner-mover-leaver list, and the prior cycle's signed-off review.
  2. Checks why the access was granted — The agent looks up access request and onboarding tickets so a permission that was deliberately granted for a documented reason is not flagged the same way as one nobody can account for.
  3. Compares holdings against the baseline — ZeroTwo groups findings into over-permissioned accounts, entitlements with no matching request, accounts belonging to departed staff, dormant accounts, and separation-of-duties conflicts, attaching the export row and ticket behind each one.
  4. Routes each proposed revocation to its owner — System and data owners get a Slack queue with keep, revoke, downgrade, and need-more-context actions. Nothing is treated as decided until an owner responds.
  5. Saves the reviewed cycle as evidence — Decisions, reviewer identity, timestamps, and the underlying export are written back to the review folder so the next cycle starts from a real baseline and auditors can see who approved what.

The agent should prepare the decision, not make it

ZeroTwo treats the entitlement export, the role baseline, the request history, and the approval channel as ingredients for one review job. Files supply what people currently hold and what the role is supposed to hold, Atlassian supplies the documented reason each grant exists, and Slack supplies the gate where an accountable owner decides. The value is in keeping those tied together per finding, so a revocation proposal always carries the evidence that produced it.

The boundary matters more here than in most workflows. ZeroTwo should not modify permissions, disable accounts, or execute revocations directly, and it should not treat an absent request ticket as proof that access is illegitimate — plenty of long-standing access predates whatever ticketing system is in use today. Unexplained access is a question for an owner, not a verdict. The agent's job is to make that question specific, evidenced, and hard to skim past.

Frequently Asked Questions

Can AI run a user access review?

It can prepare one. ZeroTwo collects entitlement data, compares it against a documented role baseline, matches each grant to its request history, and routes findings to the accountable owner. The approve-or-revoke decision stays with a person, and the permission change itself is executed in your identity system rather than by the agent.

How does ZeroTwo decide what counts as over-permissioned?

It compares what an account holds against the role baseline you supply. If you have no documented baseline, the agent can only report what exists and which grants have no matching request, which is why writing the baseline down is usually the first useful step.

Does it revoke access automatically?

No. ZeroTwo produces proposed revocations with evidence and routes them for approval. Executing the change stays in your identity provider or ticketing workflow, which keeps the audit trail in the system auditors already examine.

Which systems should be connected for this workflow?

Most teams start with the approved folder holding entitlement exports and the role baseline, an Atlassian project carrying access request and onboarding tickets, and the Slack channel where system owners already respond.

What does it do when access has no matching ticket?

It flags the entitlement as unexplained rather than as unauthorised, and asks the owner. Access granted before the current ticketing process existed is common and legitimate, so treating a missing ticket as proof of a problem would bury reviewers in false findings.

Get Started

Sample prompt: At the start of each access review cycle, read the entitlement exports and role baseline in our access review folder, match each entitlement to its access request ticket, group the accounts that exceed baseline or belong to departed staff or have no matching request, and send each proposed revocation to the owning team in Slack for a keep or revoke decision.

Runs at the start of each review cycle, then saves reviewer decisions and evidence back to the review folder.

Integrations: google_drive, atlassian, slack

Make the access review a decision, not a formality.

Connect your entitlement exports, role baseline, and approval channel. ZeroTwo keeps every proposed revocation tied to its evidence.

Explore Other Agent Workflow Categories