KeyForge AI
Access Reviews

Certifications people actually read.

The reason campaigns get rubber-stamped is that reviewers are given no basis to decide. A list of entitlement names with no risk, no usage and no comparison invites one action: approve all.

The problem

A 98% approval rate is not assurance

01

Volume without signal

Hundreds of line items, each identical in appearance. Nothing marks which five actually matter.
02

Timing without relevance

A quarterly campaign reviews a snapshot. Risk accrued the day after the last one runs unexamined for months.
03

Decisions without evidence

An approval with no justification and no attached context is not something you can defend to an auditor.
The honest measure of a campaign is its revocation rate. If almost nothing is being revoked, the review is not finding anything — it is confirming what was already there.

The approach

Micro-certifications, triggered by change

Continuous review does not replace periodic campaigns — it drains them. By the time the scheduled campaign runs, the access that changed has already been reviewed in context.

  1. 1

    Trigger

    A transfer, contract change, new entitlement or orphaned account opens a governed event.

  2. 2

    Scope

    Only the access actually affected by that change enters review — not the user's entire profile.

  3. 3

    Context

    Risk score, usage recency, peer comparison and blast radius attach to each line.

  4. 4

    Decision

    Revoke, approve with a compensating control, or accept risk with a re-attestation date.

  5. 5

    Evidence

    Justification, approver and outcome retained as the audit record for that decision.

What reviewers see

Context on every line

Risk

Scored, not alphabetical

Each item carries a risk score and severity, so the queue sorts by what matters rather than by application name.
Usage

Last used, and how often

Access granted and never exercised is the safest thing in the backlog to remove — and the easiest decision to defend.
Peers

Who else holds this

Peer comparison shows whether an entitlement is normal for the role or an outlier worth questioning.
SoD posture

Conflicts surfaced inline

If approving this line would complete a toxic combination, the reviewer sees it before they click.
Mitigation

More options than yes or no

Approve with a compensating control — time-bound, step-up, read-only — instead of a binary that forces a bad choice.
Re-attestation

Accepted risk expires

An accepted risk carries a date. It returns for review automatically rather than becoming permanent by default.

What is your current revocation rate?

If you do not know, that is the first number a governance assessment should give you.