Access Reviews Fail When Managers Don’t Have the Context to Decide

Access Reviews Fail When Managers Don’t Have the Context to Decide

Why access certification needs better business engagement, not just another campaign.

Access reviews are only useful if reviewers can make a meaningful decision.

That may sound obvious, but it is one of the most important practical challenges in access governance. Periodic access certification is designed to confirm whether users still need the access they hold. In SAP environments, that review may involve managers, role owners, business owners, security teams and control owners, depending on how the process is configured.

SAP Access Control’s User Access Review capability is described by SAP as a workflow-based review and approval process in which business managers and role owners perform periodic reviews of user access, with requests generated by the system based on the organisation’s internal control policy. SAP also describes the feature as automating and documenting decentralised user access review by business managers or role owners.

That word “review” matters. The goal is not simply to close a campaign. The goal is to obtain a defensible business confirmation that access is still appropriate.

And that is where many organisations struggle.

Access certification depends on business judgement

Access governance is often discussed in technical language: users, roles, risks, rulesets, violations, mitigations, assignments and systems. Those concepts matter. They are essential to SAP GRC, SAP Access Control and SAP Cloud Identity Access Governance.

But access certification also depends on something that is harder to automate: business judgement.

A manager may know whether a member of their team still performs a particular job. A role owner may understand whether a role is still appropriate for a function. A business owner may recognise whether access aligns with current responsibility, geography, process ownership or segregation of duties expectations.

SAP describes SAP Cloud IAG Access Certification Service as a cloud solution for periodically reviewing and certifying access rights by managers and/or designated reviewers across cloud and on-premise applications and systems. The validation is intended to ensure users have the access needed for their job function, and that access no longer needed is removed.

That makes the reviewer’s contribution central. The system can orchestrate the campaign, route work, record decisions and support auditability. But the quality of the review still depends on whether the reviewer understands what they are being asked to certify.

A manager who sees a list of users and role names may not immediately know whether each assignment is appropriate. A role owner who sees a technical role description may not know whether the named individual still requires the underlying business capability. A reviewer who is unsure may delay, escalate, approve cautiously, or ask someone else to interpret the request.

None of this means the reviewer is careless. More often, they are busy, occasional participants in an access governance process that is not part of their daily work.

Why reviewers struggle

The practical challenge is that access review items are not always easy for non-specialists to interpret.

A reviewer may be presented with a user, a role, a system and a decision to approve or remove access. That information may be technically accurate, but still not sufficient for confident business judgement. The role name may reflect an internal naming convention rather than a recognisable job responsibility. The description may be incomplete, overly technical or written for a security administrator rather than a department manager. The system name may be familiar to IT, but not to a business reviewer.

Long review lists add another problem. Even when each individual item is understandable, the cumulative effort can become substantial. A manager asked to review a small number of access assignments may give the task proper attention. A manager asked to work through a large campaign at a busy point in the quarter may find it much harder to maintain the same level of scrutiny.

There is also the issue of infrequent interaction. Many managers and role owners are not daily users of SAP GRC or SAP Cloud IAG. They may only engage with certification during quarterly, half-yearly or annual review cycles. By the time the next campaign appears, they may not remember the process, the terminology, or the significance of each action.

That uncertainty matters because access certification is not an ordinary approval. A reviewer is not just saying, “I have seen this request.” They are confirming that access remains appropriate, or that it should be removed, rejected, forwarded or otherwise handled according to the governance workflow.

For an occasional reviewer, those choices need to be clear.

Reviewer fatigue turns certification into a tick-box exercise

Reviewer fatigue is not simply a matter of workload. It is the point at which volume, ambiguity and time pressure combine to reduce review quality.

When review campaigns are large, unclear or poorly timed, reviewers may move from judgement mode into completion mode. The question shifts from “Is this access still appropriate?” to “How do I get this task off my list?”

That creates several risks. Some reviewers may approve items because they cannot see an obvious reason not to. Others may escalate too much because they are unsure. Some may delay until chased. Others may add comments that explain their uncertainty but do not resolve the underlying question. Inconsistent responses then create additional work for security, compliance and process owners.

The weakness is not necessarily in the governance platform. SAP Cloud IAG, for example, supports campaign creation, management of active campaigns, reviewer inboxes and audit/campaign logs as part of the Access Certification Service. SAP’s documentation also describes the Access Certification Audit Log as recording audit-relevant actions, including what was done, by whom and when.

The challenge is human engagement.

If the reviewer does not see the task, does not understand the item, or does not feel confident in the decision, the campaign may still complete without delivering the level of assurance the organisation expected.

Better engagement starts with better visibility

Access review tasks compete with everything else a manager has to do: operational issues, customer commitments, internal meetings, budget questions, HR responsibilities and project delivery. If certification tasks sit in a specialist work inbox that the reviewer rarely visits, they can easily be missed until reminders begin.

Visibility is therefore not a cosmetic issue. It is part of control effectiveness.

The reviewer needs to know that action is required. They need to see enough information to understand the decision. They need a convenient route to respond, or to escalate properly if they are not the right person. And the organisation needs to know what has been reviewed, by whom, when and with what outcome.

This is where Microsoft Teams can play a useful role. For many organisations, Teams is now the daily workspace for managers and operational leaders. It is where they receive internal messages, attend meetings, collaborate with colleagues and respond to time-sensitive requests.

Surfacing selected access review tasks in Teams does not change the governance system. It changes the engagement layer around the reviewer.

Better decisions need wider context, not just faster notifications

Visibility is important, but it is not enough on its own.

A review task can be surfaced promptly, appear in the right channel and still leave the reviewer uncertain. The real opportunity is to present the task with enough surrounding context to support a confident decision.

In many organisations, the information needed for a good access review decision does not sit in one place. SAP GRC or SAP Cloud IAG may hold the access review campaign, reviewer assignment, risk indicators, workflow status and certification decision. SAP S/4HANA may provide business role usage, transactional context or organisational data. HR or SuccessFactors may hold employment status, job role, department, manager and position information. IT service management tools may hold the original access request, change ticket or business justification. Identity platforms may provide sign-in, group or account status information.

A manager reviewing access may not need all of this detail. But selected context from these systems can make the review far more meaningful. For example, it may help the reviewer see whether the user is still in the same role, whether the access aligns with their current department, whether the access was originally requested for a specific project, whether there are open risk indicators, or whether the assignment appears unusual compared with the user’s current responsibilities.

This is where Looply can add value as an engagement and orchestration layer. Before presenting an access review task in Microsoft Teams, Looply can gather relevant information from multiple back-end systems, apply customer-defined logic, and present a concise, business-friendly view to the reviewer.

Used carefully, AI can take this further. Rather than forcing the reviewer to interpret separate fields, codes and comments, AI can generate a short summary of the review item and highlight specific points that may deserve attention. That might include a role that appears inconsistent with the user’s current job, a high-risk access indicator supplied by the governance system, an access assignment with limited recent usage, or a missing business justification.

The AI should not make the access decision. Nor should it replace the access-risk analysis performed by the governed SAP access management process. Its role is to summarise, clarify and draw attention to relevant signals, so the reviewer can make a better-informed decision faster.

That distinction is important. In access certification, speed without judgement is not enough. The objective is to help reviewers act quickly because the task is clear, not because the control has been simplified to the point where the decision loses meaning.

Bringing access review tasks into Microsoft Teams

Looply is designed for this engagement layer.

In an SAP GRC or SAP Cloud IAG context, the core principle should be clear: SAP remains the governed process and system of record. Access risk analysis, campaign configuration, reviewer assignment, workflow rules, decision processing, remediation and audit requirements remain governed by the customer’s SAP access governance architecture.

Looply can help by bringing selected access review notifications, actions and reminders into Microsoft Teams using Adaptive Cards and workflow orchestration. Rather than expecting occasional reviewers to keep checking a specialist inbox, Looply can make review tasks visible in a channel they already use during the working day.

But the value is not only notification delivery. Looply can also help shape the review into a more decision-ready interaction.

A Teams-based review card might show the reviewer that an access certification item requires attention. It can present concise information about the user, role or business role, system, review period and requested action. Where appropriate, Looply can also enrich the card with selected context from other systems, such as HR data, organisational information, access request history, usage indicators, ticket references or risk signals supplied by SAP GRC / SAP IAG.

This creates a more useful review experience. The manager is not simply being asked to approve or remove an unfamiliar role. They are given a clearer picture of who the user is, why the access may exist, how it relates to their current responsibilities, and whether anything appears to need closer scrutiny.

AI can also support this experience by generating a short plain-language summary of the review item. For example, it could explain that the user is in the Finance Operations team, that the access relates to supplier invoice processing, that the assignment was originally requested for a particular business activity, and that the governance system has identified a medium-risk indicator for review. The reviewer can then focus their attention on the decision, rather than piecing together context from multiple places.

The important point is that Teams does not make the risk decision. Looply does not replace SAP GRC or SAP IAG. The purpose is to make the review task easier to see, easier to understand and easier to complete, while returning the response to the governed process.

Access certification is a compliance process, not a chat message. Teams is the interaction point; Looply is the engagement and orchestration layer; SAP remains the authority.

What context helps a reviewer respond

The best review experience is not necessarily the one with the most data. It is the one that gives the reviewer enough relevant information to make the next decision.

That context may come from SAP GRC or SAP IAG, but it may also come from surrounding enterprise systems. The reviewer does not need to see the complexity of that integration. They need a concise, trustworthy view of the facts that matter.

For a manager or role owner, useful context may include the user’s name, department, job title or manager; the role or business role being reviewed; a plain-language description of what the access enables; the target system; the reason the access was originally granted, if available; the review period; any available usage indicator; and the required action.

Additional context may include employment status, position changes, project assignment, original access request details, ticket references, recent usage, SoD risk indicators, mitigation status or previous review comments. Some of this information may be useful to display directly. Some may be better summarised. Some may simply inform whether the task should be highlighted as requiring closer attention.

The design principle should be relevance, not volume. A reviewer should not have to sift through every attribute from every connected system. The card should help them understand the decision in front of them and provide a route to deeper detail when needed.

This is where AI summarisation can be especially useful. A well-designed summary can turn a set of technical signals into a short explanation: why the item is being reviewed, why it may matter, and what the reviewer should consider before responding. The reviewer still owns the judgement, but the cognitive effort required to reach that judgement is reduced.

Reducing manual chasing and improving campaign completion

One of the most visible pain points in access certification is the manual effort required to keep campaigns moving.

Security, compliance and access governance teams often spend time reminding reviewers, checking status, escalating overdue items and explaining what action is required. Even when the governance system provides reminders and escalation, process owners may still find themselves chasing key reviewers outside the system because the review is time-sensitive.

Looply can help reduce that friction by surfacing reminders in Teams, prompting reviewers before deadlines, and escalating overdue items in line with the agreed process. It can also help process owners see which tasks have been actioned and which still need attention, without relying solely on manual follow-up.

The value here is not that Teams improves the technical quality of risk analysis. The value is that review work becomes more visible, more understandable and more actionable for the people whose input is required.

For audit and compliance teams, evidence is also essential. Where Looply is used as the engagement layer, the design should support the governed audit trail by returning decisions, timestamps, reviewer identity and comments to the appropriate process, rather than creating a disconnected side record.

That is how Teams-based engagement can support access governance without weakening it.

From certification campaign to business-owned review

Access certification is often measured by campaign completion: how many items have been reviewed, how many are overdue, how many were approved, how many were removed, and whether the campaign closed on time.

Those measures matter. But they are not the whole story.

A completed campaign is only valuable if the organisation can trust the decisions made within it. That requires reviewers to understand the access they are certifying. It requires role descriptions that make sense outside the security team. It requires timely engagement from managers and role owners. And it requires a process that captures evidence without making occasional reviewers feel they are navigating an unfamiliar technical exercise.

The shift is from campaign administration to business-owned review.

In that model, SAP GRC or SAP Cloud IAG continues to provide the governance structure. Looply helps bring the reviewer interaction closer to the reviewer’s normal working rhythm, while also assembling the context needed to support a better decision. Where AI is used, it should clarify and summarise that context rather than replace the reviewer’s judgement or the governed risk analysis.

The access governance team retains control, while managers and role owners get a clearer, more accessible route to participate.

That is a more practical model for enterprise compliance. It recognises that access review quality depends not only on policy, workflow and risk rules, but also on whether the right people can understand the decision in front of them and respond with confidence.

Get Started

Access reviews should not become a quarterly or annual exercise in chasing busy managers through unfamiliar screens. They should be a meaningful business control, supported by clear context, visible tasks and reliable evidence.

Arch helps SAP customers extend governed SAP processes into Microsoft Teams using Looply, while keeping SAP GRC, SAP Access Control or SAP Cloud IAG as the process of record. For access certification, that means more than moving a task into Teams. It means creating a decision-ready review experience: selected data from the right systems, concise context, timely reminders, clear actions and evidence returned to the governed process.

If your access review campaigns are completing slowly, generating too much manual follow-up, or leaving reviewers unsure what they are being asked to certify, it may be time to look at the engagement layer around the process.

Speak to Arch about how Looply can help bring selected SAP access review tasks, enriched context, AI-assisted summaries and reviewer responses into Microsoft Teams — without replacing the governance system that controls them.