๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

Access reviews & certification

Prove who can touch what, and that someone checked.

“Do a quarterly access review” is easy to write into a policy and painful to actually run. Lavawall® turns it into a structured workflow across SharePoint, Teams, and Entra, surface access, route recertification to the right approver, and keep the evidence auditors want.

Start my free trial, no credit cardMap it to a framework

SharePoint · Teams · Entra · approver workflow · audit trail

Watch an access reviewVideo coming soon

From “we should” to done and evidenced

See who has access to what

Access across SharePoint, Teams, and Entra, gathered into one view, not a dozen admin centres and a spreadsheet you rebuild every quarter.

Route recertification to the right person

Send each entitlement to the approver who actually knows whether it belongs, and capture their keep / remove / escalate decision with a full audit trail.

Catch orphaned and over-privileged accounts

Dormant accounts, access that outlived a role change, and entitlements that drifted past least privilege get surfaced so the review is a real cleanup, not a rubber stamp.

Evidence auditors accept

Every review is timestamped and exportable, the recurring artifact SOC 2, HIPAA, NIST 800-171, and CMMC assessors ask for, produced as a by-product of doing the work.

an access review with approver decisions

Manage users and access across every tenant

Access Review sits on top of Lavawall®’s multi-tenant user management for MSPs, so the same console that shows who has access also governs how they sign in. Add a user to a tenant company, or to the parent MSP company so the grant cascades to its child companies, and set exactly how much they can do.

Secure by default, weak options flagged in red

Lavawall follows Minimum Viable Secure Product (MVSP) principles: SSO is the recommended path, passkeys and MFA are on by default, and passwords are treated as optional and discouraged, with the less-secure choices highlighted in red.

  • Single sign-on (SSO)
  • Passkeys by default
  • MFA built in
  • Passwords optional, flagged red

Right-sized permissions, from full admin to read-only

Grant full administrative control, report-only access, read-only client viewing, or co-management that stops short of editing users, so every reviewer and client contact sees exactly what they should, and nothing they shouldn’t.

Lavawall multi-tenant user management for MSPs
authentication methods with less-secure options highlighted in red
granular per-user permission levels from full admin to read-only

Want your review program designed and run?

ThreeShield, the CISSP/CISA team behind Lavawall® will define the cadence, set the approver map, and run the recertification with you so it satisfies the auditor the first time.

Common questions

What does an access review produce?
A timestamped record of who has access to what across SharePoint, Teams, and Entra, the approver decisions, and the evidence auditors ask for.
Does it catch orphaned and over-privileged accounts?
Yes, dormant accounts, access that outlived a role change, and entitlements past least privilege are surfaced for real cleanup.
Is it gated by subscription?
Access Review is enabled per company in billing, so what you see reflects what that tenant is actually subscribed to.

Start my free trial →