Planning for and automating access reviews
In terms of an access life cycle, you should consider the access life cycle of your member users and your guest users, and especially your privileged administrators. These should be handled differently, as the life cycle of our member users is based on employment within the company being terminated or changes in a role, and the access that is required for the department or team that they belong to. Guest users are provided access based on a partnership and external collaboration trust relationship. Chapter 12, Planning and Implementing Entitlement Management, discussed using access reviews for member and guest user entitlements.
Privileged administrative user access should be regularly reviewed in a similar manner. Since these are elevated access assignments, the review of these should be done on a consistent basis as identified by the policies of the company. Unused and unnecessary privileged assignments should be removed as soon as possible...