How to Complete an Access Review Request From Your Manager
This guide is for anyone who has received an access review request from their manager and needs to finish it correctly without guessing. You will learn exactly where to click, what to approve or remove, and how to confirm your review was submitted.
TL;DR — An access review is a request to confirm whether someone still needs the apps, groups, or roles they can use. Open the review link from your manager or identity provider, check each person or access item one by one, choose Approve only for access that is still needed now, choose Deny/Remove for anything no longer needed, and submit the review. Reading time: ~5 min
Goal
When you finish, the access review will show as Completed or Submitted in your company's identity system, and the people or access items in that review will be marked as approved or removed based on your decisions.
Prerequisites
- The access review email, chat message, or task notification your manager sent you
- Your work account login for your company's identity provider (the sign-in system), such as Microsoft Entra, Okta, Google Workspace, or a similar tool
- Multi-factor authentication (MFA, a second sign-in check) device if your company requires it
- The names of the people, groups, apps, or roles you are expected to review
- A browser updated in 2026, such as Chrome, Edge, Firefox, or Safari
- If available, your company's reviewer instructions or policy for when to approve vs remove access
Steps
Step 1: Open the access review request
Use the link in the email or message your manager sent you.
If you do not have a direct link, open your company's identity provider dashboard and look for a task area such as:
Your provider's dashboard → Tasks / Approvals / Access Reviews / My Reviews
Examples of common labels:
Microsoft Entra: My Access → Access reviews
Okta: Dashboard → Tasks or Approvals
Google Workspace or another provider: use the review link from the email notification
What you should see when this succeeds: a page listing one pending review, or a table of users/access items with buttons such as Approve, Deny, Keep, Remove, or Submit.
Step 2: Sign in with your work account
If prompted, sign in with your company email address and password, then complete MFA.
Email field: your work email address
Password field: your normal work password
MFA: approve the sign-in in your authenticator app, text message, or hardware key
What you should see when this succeeds: the review page opens and shows the review name, due date, and the list you need to decide on.
Step 3: Read the review scope before changing anything
At the top of the review, identify exactly what you are reviewing. Common examples are:
Users in a group
Users assigned to an application
Users with a privileged role
Guest users with external access
Then check the columns shown on screen. Typical columns are:
Name
Email
Access type / Role
Last sign-in
Reason / Justification
Recommendation
What you should see when this succeeds: you know whether you are reviewing people, app access, group membership, or admin roles, and you can see each row that needs a decision.
Step 4: Review each item and choose the literal action
For each row, use the action button shown in your system. Pick the exact decision that matches the current need:
Approve / Keep — the person still needs this access today for their job
Deny / Remove — the person no longer needs this access, changed jobs, left the team, or you do not recognize the need
Don't know / Not sure — use only if your system offers it and your company allows it
If your tool asks for a reason, enter a short plain-language note such as:
Still supports payroll reporting
Still needs access for customer onboarding
No longer on this project
Role changed in May 2026
Unknown user; removing access pending re-request
What you should see when this succeeds: each row changes from Pending to your selected decision, or a checkmark appears next to the item.
Step 5: Use bulk actions only if every listed item should get the same decision
If the page offers a bulk action, use it only when all visible items should be approved or all should be removed.
Typical menu paths look like:
Select all rows → Approve
Select all rows → Deny / Remove
Bulk actions → Approve selected
Bulk actions → Remove selected
⚠️ Bulk actions can remove access for multiple people at once. If even one row should be different, review items one by one instead of using Select all.
What you should see when this succeeds: all selected rows show the same decision, and there are no remaining Pending items unless you intentionally left some for later.
Step 6: Submit the review
After every row has a decision, submit the review.
Typical button labels are:
Submit
Complete review
Apply decisions
Save and submit
If a confirmation window appears, click:
Confirm
Submit review
Yes, submit
What you should see when this succeeds: the review status changes to Completed, Submitted, or No pending decisions.
Step 7: Tell your manager only if the review includes unclear items
If you found users or access you could not confidently approve or remove, send a short message after submitting, or before submitting if your company requires clarification first.
Copy and paste this template into email or chat:
I completed the access review. I removed access that is no longer needed and approved current access. One item may need follow-up: [name or role]. Reason: [short reason].
What you should see when this succeeds: your manager has the context needed to handle exceptions without reopening the whole review.
Verify it works
Use these checks to confirm the review is fully done end to end:
- Reopen the same review link.
- Confirm the status near the top says one of the following:
Completed
Submitted
Closed
No pending decisions
- Confirm there are no rows marked:
Pending
Not reviewed
Awaiting decision
- If your system has a history or audit area, open:
Review page → History / Activity / Decisions
Expected result: you can see your name, the date/time, and the decision recorded for each item.
Common pitfalls
You approve everything without checking whether the person still needs access
Mistake: using Approve all because it is faster.
Symptom: former team members, contractors, or people who changed roles keep access they should have lost.
Fix: reopen the review if still possible, change the incorrect rows to Deny/Remove, and submit again; if the review is already closed, message your manager or access admin with the exact names to remove.
You remove access because you do not recognize the name, but it is a shared service or admin account
Mistake: treating every unfamiliar entry as a person.
Symptom: an automation, integration, or service account loses access and a workflow breaks.
Fix: check the row details for labels like service account, automation, integration, or a non-human email address before choosing Deny/Remove; if unclear, ask your manager before submitting.
You leave rows as pending and think the review is done
Mistake: clicking away after making some decisions but not pressing Submit.
Symptom: the review still appears in your task list, or your manager says it is incomplete.
Fix: reopen the review, finish every pending row, then click Submit or Complete review and wait for the status to change.
You review the wrong thing: app access vs group membership vs privileged role
Mistake: assuming all access has the same impact.
Symptom: you approve a powerful admin role because the user needs the app, but they only needed normal user access.
Fix: read the review title and the Access type / Role column first; approve only the exact role shown, not the person's general need for the system.
You wait until after the due date
Mistake: opening the email, planning to do it later, and missing the deadline.
Symptom: the review link no longer accepts changes, or the system auto-applies default decisions.
Fix: if the review is still open, submit it immediately; if it is closed, send your manager the names and exact approve/remove decisions so an admin can apply the corrections manually.
You use old browser tabs and see stale status
Mistake: checking a tab that was open before you submitted.
Symptom: the page still shows Pending even though you already completed the review.
Fix: refresh the page once, or close the tab and reopen the original review link to load the current status.
This article was written by an AI system and published pending human review. Verify anything you intend to act on.
Have a project in mind?
Get an instant AI price estimate for it, or talk directly to our team.
One email a month on what we learn building with AI