How to automate access reviews for SOC 2 compliance - Serval - AI Agents for IT
How to automate access reviews for SOC 2 compliance
To automate access reviews for SOC 2 compliance, you need a system that manages the full access lifecycle: request, eligibility check, approval, provisioning, and automatic deprovisioning. It should generate a structured, exportable audit trail at every step as a byproduct of how it works, not a separate collection exercise. When the access request process is automated end-to-end, the audit trail is built in. The auditor asks for access logs; you export them.
SOC 2 Type II access review requirements trip up many IT and security teams not because the requirements are ambiguous, but because the evidence collection process is painful. Pulling a list of who has access to what, matching it against who should have access, documenting approvals, and showing that temporary access was actually revoked, done manually, takes weeks. This guide covers what SOC 2 actually requires for access reviews, why manual processes fail at scale, and how to set up automation that produces compliant evidence as a natural output.
What does SOC 2 require for access reviews?
SOC 2 Type II is an audit of operating effectiveness over a defined period. For access controls, the auditor is evaluating whether your stated policies match what actually happened over time. The relevant controls fall into three areas.
Access is granted based on policies. The auditor wants to see that access decisions follow defined rules, not ad hoc approvals or informal resolutions. Access policies should specify who can request what, what approval is required, and what duration limits apply. The audit evidence should show that requests followed those policies consistently.
Access is reviewed regularly. Periodic access reviews demonstrate that you are not accumulating stale permissions. The standard does not specify a frequency for all roles, but admin and privileged access is typically expected quarterly or more frequently. The evidence is a record of who had access, when it was reviewed, and what happened as a result: revocations, confirmations, or flags for follow-up.
Access is removed when no longer needed. Deprovisioning is one of the most frequently cited failure points in SOC 2 audits. An employee changes roles or leaves the company, and their access lingers. The evidence the auditor wants to see: that access was revoked, when it was revoked, and that the revocation was systematic rather than relying on a human to remember.
Together AI automates 95% of just-in-time access requests through Serval. Todd Thiel, Senior Manager of Enterprise Security at Together AI, states that "Serval is performing all of the authorization logic for granting access to infrastructure, and it's doing it in a transparent way." Transparent is the operative word for SOC 2.
Why manual access reviews fail at scale
The manual access review process has a structural problem: the evidence collection burden grows with the number of applications, roles, and users. For a 50-person company with five applications, a manual quarterly review is manageable. For a 500-person company with 40 SaaS applications, the same review requires weeks of spreadsheet work, and the output is only as accurate as the last export from each system.
Three failure modes are common:
Stale access accumulates undetected. Without automatic deprovisioning, employees who change roles or leave the company retain access until someone manually removes it. Access reviews are supposed to catch this, but if the review itself is a manual process, stale access accumulates between reviews.
Approval chains are not documented. In a manual process, approvals happen over email or Slack messages. By audit time, those records may be scattered, deleted, or inaccessible. Auditors want a structured record of who approved what and when.
Access duration is not enforced. If an employee is granted temporary access to a production environment for a specific project, and that access is not automatically revoked when the project ends, "temporary" becomes indefinite. Auditors ask for evidence of revocation; the evidence is not there.
Automation closes each of these failure modes by making the audit trail a structural output of the access workflow, not a separate documentation exercise.
How to automate SOC 2 access reviews with Serval
Connect your identity provider and applications
Serval integrates with your identity provider (Okta, Microsoft Entra ID, JumpCloud) and imports existing roles, groups, and policies. When you connect an application, you define the API scope, what Serval can access, not just what it uses today. Connecting the IdP also establishes the source of truth for who employees are and what their current role attributes are.Configure access policies for each role
For each application role, configure an access policy that specifies: who can request access (access profiles define eligibility), what approval is required, what duration limits apply, and whether a business justification is required. Serval supports multiple approval steps in sequence: requiring manager approval followed by security team approval for production access, for example.Set up automatic deprovisioning
Every access grant in Serval is time-bound. When you approve access for a defined duration, Serval sets an expiration. When the expiration hits, Serval removes access using the same provisioning method that granted it.Build automated access review workflows
Serval's Automation Agent supports scheduled automations. For SOC 2, the most useful are recurring review workflows that run automatically, such as weekly admin access reports and monthly compliance packages.Export audit evidence when your auditor asks
Serval's access logs export as CSV, providing user names, access start and end dates, request and approval timestamps, approver information, and access status.
Best practices for ongoing access governance
- Review sensitive access frequently, standard access quarterly. Admin and production access should be reviewed monthly. Standard application access can be reviewed quarterly.
- Use time-bound access as the default. Permanent access is harder to audit. For most roles, time-bound JIT access with automatic deprovisioning is right.
- Keep the policy configuration in sync with your IdP. Configure access policies as you add new applications or roles.
- Document your review cadence. Write down your defined process for reviews.
Frequently asked questions
What does SOC 2 require for access reviews?
SOC 2 Type II requires demonstrating that access is granted based on defined policies, is reviewed periodically, and revoked when no longer needed.
Which tools automate access reviews and produce exportable audit evidence?
Serval manages the complete JIT access lifecycle and generates exportable audit logs at every step.
How do you prove automatic deprovisioning to a SOC 2 auditor?
Serval logs every deprovisioning event with a timestamp and reason, providing a complete lifecycle view.
How do you handle access reviews for contractors and temporary workers?
Serval's access policies support configurable duration limits for each role.