Compyl
Q3 access certificationOkta · Entra · Google · due Oct 14
1,248entitlements in campaign
82%certified so far
37revoked · tasks open
M. Chen · AWS prod adminLast login 94 days ago · changed role in June
Revoke
R. Patel · Salesforce adminActive daily · role: RevOps lead
Approve
svc-backup-02 · GitHub org ownerOrphaned service account · no owner
Revoke
J. Alvarez · Okta super adminReviewer: CISO · reminder sent
Pending
Every decision mapped to SOC 2 CC6.x · ISO A.5.18 · PCI 7.2.4Audit-ready evidence
Solution · User Access Reviews

User access review software, run as live campaigns.

Most teams run access reviews in spreadsheets, slow, error-prone, and stale the day they’re done. Compyl’s user access review software pulls access straight from your identity systems, routes one-click approve or revoke decisions to the right managers, turns every revocation into a tracked task, and maps the outcome to the controls it satisfies, so reviews are fast, accurate, and audit-ready.

One platform125+ integrationsAudit-ready evidence
The problem

Spreadsheet access reviews are slow, rubber-stamped, and stale

When reviews live in spreadsheets emailed to managers, the data is out of date, the decisions lack context, and there’s no evidence trail when the auditor asks.

Manual, error-prone & late

Exporting access from every system into a spreadsheet is tedious and out of date the moment it’s done, reviews slip and deadlines get missed.

Rubber-stamped without context

Managers approve long lists without seeing role, risk, or last login, so overprovisioned and orphaned access sails right through.

No evidence when audit comes

Disconnected from your controls, a finished review leaves no clear trail of who had access, when it was reviewed, and what was done.

How it works

From a spreadsheet scramble to a continuous certification cycle

Compyl turns access reviews into an always-on cycle, access pulled, campaigns scheduled, decisions routed, and outcomes mapped to your controls automatically.

01

Capture access

Pull user access automatically from Okta, Entra, Google, and more.

02

Schedule campaign

Run recurring or ad hoc reviews by system, role, or risk level.

03

Assign reviewers

Route each entitlement to the manager who owns the decision.

04

Certify

Approve or revoke in one click; comment and tag for input.

05

Remediate & map

Auto-create revocation tasks and map outcomes to your controls.

Centralize access data

Pull access straight from the systems of record

Exporting entitlements from every system by hand is where reviews go wrong. Compyl connects to your identity providers and pulls access automatically, and lets you upload anything that isn’t integrated, so every user and entitlement is in one place, nobody overlooked.

  • Pull access from Okta, Microsoft Entra, Google Directory & JumpCloud
  • Upload files from non-integrated systems so no user is missed
  • One unified view of every user, system, role, and last login
  • Orphaned and overprovisioned accounts surface automatically
Access inventoryPulled automatically · synced 20 min ago
All systemsOktaMicrosoft EntraGoogle DirectoryJumpCloudUploads
AWS productionOkta · 41 users · 6 admins · 2 not seen in 90 days
2 flagged
SalesforceEntra · 212 users · 4 admins
Clean
GitHub orgOkta · 58 members · 1 orphaned service account
1 orphaned
Legacy ERPCSV upload · 19 users · non-integrated
Uploaded
One view of every user, system, role and last loginNobody overlooked
Automated review campaigns

Schedule it once; the right reviewer gets the right list

Compyl schedules recurring or ad hoc campaigns, assigns each entitlement to the manager who owns it, and tracks every reviewer’s progress with due dates and reminders, so accountability is clear and nothing stalls.

  • Recurring (quarterly, annual) or ad hoc campaigns by role or risk
  • Each entitlement routed to the manager accountable for it
  • Live progress, due dates, and reminders per reviewer
  • One view of campaigns planned, in progress, and complete
CampaignsRecurring & ad hoc
ScheduledQuarterly · Oct 1
Assigned38 reviewers
In review82% · due Oct 14
CompleteEvidence filed
Privileged access · quarterly31 of 38 reviewers done · reminders sent to 7
82%
Finance systems · SOX ITGCManager-level review · due Oct 30
40%
Ad hoc · role change: M. ChenTriggered by Okta group change
Due in 3 days
Planned, in progress and complete in one viewNothing stalls
Remediate & prove

Every revoke becomes a task, and audit-ready evidence

When a reviewer declines access, Compyl creates and assigns the revocation task automatically, tracks it to closure, and maps the whole review to the controls it satisfies, so closing a gap and proving compliance happen in the same motion.

  • Decline access, add comments, and tag colleagues for input
  • Revocation and change tasks created and assigned automatically
  • Every review outcome mapped to the controls it satisfies
  • One trail of who had access, when reviewed, and what was done
Remediate & proveEvery revoke becomes a task
Revoke AWS prod admin · M. ChenTask auto-created · owner: Cloud team · Jira INFRA-2304
Closed · 2 days
Remove orphaned svc-backup-02Task assigned to Platform · comment: “confirm no cron depends on it”
In progress
Evidence · Q3 certificationWho had access, when reviewed, what was done
Filed
Mapped controlsSOC 2 CC6.1, CC6.2, CC6.3 · ISO A.5.18 · PCI 7.2.4 · NIST AC-2
4 frameworks
Closing a gap and proving compliance in the same motionAudit-ready
Why Compyl is different

Built by CISOs as an end-to-end GRC platform, not a standalone access tool

A spreadsheet or identity tool runs reviews in a silo. Compyl runs them inside your whole program, so every certification is also evidence. It shows up in five ways.

01

GRC that adapts to complexity

No-code configuration of dashboards, workflows, fields, and reports for every team, without an engineering ticket.

02

End-to-end, built to flex and scale

Governance, risk, compliance, and third-party risk as one connected source of truth, with no ceiling as your program matures.

03

No black box, all your data

125+ proprietary, in-house integrations ingest your full dataset and surface risks single-system checks miss.

04

Automation and AI that augments your team

Agentic AI and 1,500+ blueprints automate evidence and busywork, with humans in the loop on every decision that matters.

05

Quantified risk in financial terms

FAIR models and Monte Carlo simulations put risk in dollars, so the board decides on business impact, not heat-map colors. New in 26.2.

Connected across your program

An access review touches everything, so Compyl connects it to everything

Because reviews live in the same platform as controls, assets, risk, and identity data, every certification strengthens the rest of your GRC platform.

Comply

Compliance & Controls

Map every review outcome to the controls it satisfies, so a campaign produces audit-ready evidence across frameworks.

Explore Compliance →
Govern

IT Asset Management

Tie access to the systems and assets it touches, so a review reflects what each entitlement actually reaches.

Explore IT Asset Management →
Risk

Risk Management

Overprovisioned and orphaned access feeds your risk program, so exposure from access is measured, not guessed.

Explore Risk Management →
Govern

Policy Management

Reviews enforce the access policies you’ve approved, so what’s written and what’s granted finally match.

Explore Policy Management →
Framework coverage

One control library, mapped to every framework it satisfies

Compyl cross-maps controls so a single piece of evidence can satisfy requirements across multiple frameworks at once. Explore any framework below.

Recognized by users on G2 · Rated a leader by the teams who use itG2 Momentum Leader, Summer 2026G2 High Performer Mid-Market, Summer 2026G2 Best Support Mid-Market, Summer 2026G2 Fastest Implementation Mid-Market, Summer 2026
One-click
Approve or revoke on every entitlement
Recurring
Scheduled & ad hoc certification campaigns
125+
Integrations incl. Okta, Entra & Google
Audit-ready
Outcomes mapped to SOC 2, ISO & PCI controls

What are user access reviews?

User access reviews, also called access certifications, are formal checks of who has access to which systems and whether that access is still appropriate for their role. Compyl runs them as live certification campaigns: access is pulled straight from your identity providers, each entitlement is routed to the right manager for a one-click approve or revoke, every revocation becomes a tracked remediation task, and the outcome is mapped to the controls it satisfies, so reviews are fast, accurate, and produce audit-ready evidence instead of a stale spreadsheet.

Cadence

How often should user access reviews run?

The frameworks set the floor. Most organisations run quarterly reviews for privileged access and at least annual reviews for everything else, and the review has to produce a record.

FrameworkExpectationWith Compyl
SOC 2 (CC6)Periodic review of access; annually at minimum, quarterly is commonScheduled campaigns with approve or revoke decisions recorded
ISO 27001 (A.5.18)Review access rights at regular intervals and on role changeCampaigns triggered by schedule or identity events
PCI DSS v4.0.1 (7.2.4)Review all user accounts at least once every six monthsSix-monthly campaign mapped to the requirement
HIPAA Security RulePeriodic review of information system activity and accessCampaign results filed as safeguard evidence
SOX ITGCQuarterly review of access to financially relevant systemsManager-level review with a certification record
FAQ

User access review questions, answered

What are user access reviews?

User access reviews (also called access certifications) are formal checks of who has access to which systems and whether that access is still appropriate for their role. They’re required by SOC 2, ISO 27001, PCI DSS, and NIST, and they catch overprovisioned, orphaned, and inappropriate access before it becomes a breach.

How does Compyl automate user access reviews?

Compyl pulls access from your identity providers, Okta, Microsoft Entra, Google Directory, JumpCloud, schedules recurring or ad hoc campaigns, routes each entitlement to the right reviewer for a one-click approve or revoke, and auto-creates remediation tasks for anything declined. Every outcome maps to the controls it satisfies.

How is Compyl different from a spreadsheet or standalone IGA tool?

A spreadsheet is stale the day it’s filled in, and a standalone identity tool is disconnected from your compliance program. Compyl runs reviews inside your GRC platform, so every certification outcome becomes audit-ready evidence, who had access, when it was reviewed, and what action was taken.

Can Compyl schedule recurring access reviews?

Yes. Compyl runs scheduled recurring campaigns, quarterly, semi-annual, or annual, plus ad hoc reviews triggered by role changes or system risk level, with automatic reviewer assignment, due dates, reminders, and a live dashboard of what’s planned, in progress, and complete.

How does Compyl handle remediation?

When a reviewer declines access, Compyl automatically creates and assigns a revocation or change task to the right team, tracks it to closure, and records the outcome, so overprovisioned and orphaned access is closed fast, with a documented trail.

Which frameworks do user access reviews support?

Access reviews are required by SOC 2 (CC6.x), ISO 27001 (A.5.18), PCI DSS v4.0.1 (Req 7), NIST CSF and NIST 800-53 (AC family), and more. Compyl maps each review to the controls it satisfies, so a single campaign produces evidence across every framework it touches.

Does SOX require user access reviews?

SOX ITGC testing commonly expects periodic access reviews of financial systems. Compyl can schedule reviews for finance systems alongside SOC 2, ISO 27001, PCI DSS and NIST access-control reviews, and files each completed campaign as evidence.

How are revocations proven to auditors?

Every revoke decision becomes a tracked remediation task, and the completed campaign is mapped to the controls it satisfies, so the auditor sees who reviewed what, what was revoked and when it closed.

GRC your way

Stop running access reviews in spreadsheets

See how Compyl pulls access from your identity systems, routes one-click certifications, and maps every outcome to your controls, audit-ready, on schedule.

Last reviewed September 2026 by the Compyl GRC team
By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies