Access Reviews
Access reviews are a formal process for periodically confirming that the right people still have access to each SharePoint site. Instead of assuming access is always correct, access reviews create a regular checkpoint where site owners verify their member list.
Why Access Reviews Matter
People's roles change. Projects end. Employees move departments or leave the company. Without regular reviews, your SharePoint sites accumulate "ghost" members - people who no longer need access but still have it.
Access reviews are required by many compliance frameworks including:
- ISO 27001 - Information security management
- SOX - Sarbanes-Oxley financial controls
- HIPAA - Healthcare data protection
- GDPR - Data privacy regulation
Tenaxis automates the scheduling, notification, and enforcement of access reviews, making compliance far easier.
Setting Up Access Reviews
- Go to Settings (bottom of the left sidebar)
- Scroll to the Access Reviews section
- Toggle Enable Access Reviews to ON
- Configure:
| Setting | Options | What it means |
|---|---|---|
| Frequency | Monthly, Quarterly, Annually | How often reviews are triggered |
| Review Due Days | Number of days (default: 14) | How long site owners have to complete each review |
| Require OTP | On / Off | Whether owners must verify their identity with a one-time code before submitting |
- Click Save
How the Review Process Works
1. Review Cycle Created
At the configured frequency (or when manually triggered), Tenaxis automatically creates a review for each site. Each review has:
- A unique, private link sent to the site's owners by email
- A due date (based on your "Review Due Days" setting)
- A list of the site's current members
2. Owner Receives Email
The site owner receives an email:
"Your access review for [Site Name] is due by [Date]. Please review who has access and confirm or remove members as appropriate."
The email contains a direct link to the review page. The owner does not need to log into Tenaxis - the link takes them directly to the review interface.
3. Owner Reviews Members (with optional OTP verification)
If OTP is enabled:
- Owner clicks the link
- They see a "Send verification code" button
- Tenaxis emails a 4-digit code to their address
- They enter the code to access the review
On the review page, the owner sees a list of all current members with their roles. For each person, they choose:
- Keep - This person should continue to have access
- Remove - This person should be removed from the site
4. Owner Submits the Review
Once all decisions are made, the owner clicks Submit Review.
- Members marked Remove are automatically removed from the site by Tenaxis
- The review is marked Completed
- Admin receives a notification that the review was completed
- Any webhook configured for review completion will fire
- The full review record (who reviewed, each decision, timestamp) is saved in the audit log
5. If Not Completed in Time
If the owner doesn't complete the review before the due date, the review status changes to Expired. Admins are notified and can:
- Cancel the expired review
- Trigger a new review cycle manually
- Escalate by contacting the site owner directly
Viewing Access Reviews (Admin)
Go to Access Reviews in the left sidebar.
You'll see a list of all reviews with:
| Column | What it means |
|---|---|
| Site | Which site the review is for |
| Cycle ID | The review period (e.g., "2026-Q2") |
| Status | PENDING, COMPLETED, or EXPIRED |
| Reviewer | The site owner who was asked to review |
| Due Date | When the review must be completed |
| Completed | When it was actually completed (if done) |
Filtering Reviews
Use the filter controls to view by:
- Status - Show only pending, completed, or expired reviews
- Site - Filter to reviews for a specific site
Manually Triggering Reviews
You can trigger an access review cycle at any time, without waiting for the scheduled interval:
- Go to Access Reviews
- Click Trigger Reviews Now
- Tenaxis creates a new review for every site and sends emails to site owners
This is useful for:
- Unscheduled compliance audits
- Responding to a security incident
- Onboarding a new compliance requirement
Canceling a Review
To cancel a pending review that's no longer needed:
- Go to Access Reviews
- Find the review
- Click Cancel (or the X icon)
- The review status changes to EXPIRED and no further action is taken
OTP Verification Explained
When Require OTP is enabled, owners must verify themselves before they can see or submit a review. This is a "non-repudiation" measure - it proves that the actual owner completed the review, not just someone who had access to the email link.
How it works:
- Owner opens the review link
- They see a form asking them to request a verification code
- A 4-digit code is emailed to the owner's M365 email address
- They enter the code - it's valid for 10 minutes
- On successful entry, they can proceed with the review
The OTP hash (a scrambled version of the code - never the code itself) is stored in the database alongside the review record. This means:
- Tenaxis never stores the actual OTP
- The review timestamp and identity are provable for compliance audits
Audit Trail
Every access review action is recorded in the Audit Log:
- When the review was created (by system or admin)
- When the owner opened the review link
- Each KEEP / REMOVE decision
- When members were removed as a result
- Who took each action
This creates a complete, tamper-evident record suitable for compliance audits.
For Site Owners: Completing Your Access Review
If you receive an email asking you to complete an access review, here's what to do:
- Click the link in the email - you don't need a Tenaxis login
- If asked, click Send Verification Code and enter the 4-digit code emailed to you
- Review the list of people who have access to the site
- For each person, click Keep or Remove based on whether they still need access
- Once you've made all decisions, click Submit
That's it. Anyone you marked "Remove" will automatically lose access to the site. You'll see a confirmation page when it's done.
Tips for owners:
- If you're unsure about someone, click Keep and reach out to them separately
- If someone definitely no longer needs access (e.g., left the project, moved departments, left the company), click Remove
- If you're the only owner and remove yourself, you'll lose access to the site - be careful