Access reviews were designed around a the idea that every identity belongs to a person.
Service accounts don't have managers. OAuth tokens don't have offboarding triggers. API keys don't map to anyone in your HR system.
The governance model simply doesn't transfer cleanly to machines & without visibility into what's actually there, review season becomes a lot of approving things nobody fully understands.
Auth Sentry Monitor is free: gethumming.io/Monitor/
#IdentitySecurity #ITDR #CyberSecurity