The person doing your access review has never heard of governance

That is not a criticism of them. It is the design flaw that has been quietly killing access reviews for years, and it is the thing we set out to fix. Reviews is live in the Rencore Teams App.
One of our early access customers is a large enterprise, ten years into SharePoint. Workspaces built up a project at a time by people who have long since moved on. Somewhere in there, a lot of content had been shared with “Everyone”. Nobody could tell you how much, or which.
For a decade that was a hygiene item. Untidy, on the list, never urgent. Then they started rolling out Microsoft 365 Copilot, and the same content stopped being a backlog and started being an answer. Copilot surfaces whatever a person can already reach. A permission nobody had looked at in years was suddenly a search result in front of a colleague who was never meant to see it.
Here is the part that stayed with me. This was not a company that did not know it should review access. They knew. They had tried. The reviews just never got finished.
So before we built anything, we went and asked why. Not in a workshop with the governance team, who are perfectly capable and were never the problem. We went to the people who actually receive the review request: the workspace owners. The team lead who set up a Teams channel for a product launch three years ago. They have owned it ever since, without once thinking of themselves as an owner of anything.
They never bought a governance tool. They have no interest in governance. And they are the single point of failure in the entire control.
Three barriers, and only one of them is the killer
When we pulled the problem apart, three things were stopping reviews. Two of them are the ones everybody talks about. The third is the one that actually decides whether the control works.
The first is commitment. Reviews were all or nothing in scope, so an admin who only wanted owners confirmed often started nothing at all. All or nothing scope turns a routine into a project. The admin looks at the size of it, decides to do it properly next quarter, and starts nothing. That one stops reviews starting.
The second is expertise. The review assumed the reviewer understood governance jargon, SharePoint groups and sharing risk. They do not, and should not have to. The reviewer opens the request, meets language built for a governance specialist, and cannot tell whether what they are looking at is a problem. So they do nothing, and nothing is the safest-feeling option available to them.
The third is the interface. A dense tree-grid built for governance specialists, handed to somebody who is not one. That is fine for a person who reads permission models for a living. For a team lead with fifteen minutes, it is a wall. Together with expertise, that one is the real killer, because both of them stop reviews finishing.
The distinction matters. The first barrier is an admin problem and it stops reviews starting. The second and third are reviewer problems and they stop reviews finishing. A review that silently never finishes is worse than one that never starts, because everyone assumes it is handled. The dashboard says a review is out there. Nobody is told that it died on contact with a real person.
We had been handing the most critical person in the process a tool built for somebody else.
So we moved the review to where the reviewer already is
The single decision that changed the most was to turn the review into a guided, step-by-step task inside Microsoft Teams. Not a link in an email to a specialist portal. The task itself, in the app they already have open.
That matters for a boring reason: no separate tool, no extra login, no training session. Nobody has to be taught anything before the control can work.
Here is what lands in front of them. The task opens on the workspace, its privacy setting, its sensitivity label, when it was last used and the due date. Then it walks through the steps the admin put in scope, one at a time.
Owners comes first, meaning whoever can manage the workspace, with each person’s name, job title and role. Members follows, covering everyone who can reach the conversations, files and channels. Guests are reviewed here too, listed with the role Guest rather than hidden on a screen of their own. Visitors covers read-only access to the connected SharePoint site.
Then two steps about the workspace rather than the people in it. Site access lists the groups, SharePoint groups and individuals holding their own permissions on the site. File access lists files shared outside the workspace through sharing links, sorted into anonymous, external, organization-wide and internal.
The last step is a summary of what they changed, and nothing else. Then a comment for the administrator, then complete. A tightly scoped review takes a few clicks inside Teams.
The reviewer acts in place rather than raising a request with somebody else. They confirm, remove or add people at every step. Leaving a row alone is how they confirm it. A workspace with nothing to change takes seconds. At the end they can archive or delete the workspace where the admin has enabled it. They can also reject the review, which is a valid answer rather than a failure. If a review lands on the wrong person, the useful thing is to say so.
One detail matters more than I expected. The brief at the top of the review is written by the customer’s own IT team, not by us. Admins fill it in per schedule, in their own words, naming their own projects and policies. So the reviewer reads guidance from people they know, which beats anything a vendor could write for them.
A workspace can also carry more than one reviewer, and the review resumes wherever the last person left it. That removes the obvious weakness in a design built around a single owner. If the owner is on leave, a colleague picks it up and carries on.
Start where you are comfortable
We also killed the all-or-nothing scope. An admin sets a schedule at whatever scope they are ready to defend, and grows it cycle on cycle. Reviewing owners only is a respectable place to start. It beats the review you keep postponing until you can do the whole thing properly.
Owners are always confirmed. Members with guests included, visitors, site access and file access are each optional. Whatever the admin ticks becomes the steps the reviewer walks through, in that order, followed by the summary. An owners-only schedule gives the reviewer one screen and a summary.
The bit everybody used to ignore
There was a third gap, and it is the one I would have missed if we had only talked to reviewers. Make starting easy and make finishing easy, and some reviews will still die, because ignoring one used to cost nothing. Previously an expired review did precisely nothing. No follow-up, no escalation. An ignored review looked identical to a completed one.
Now an ignored review triggers action. I want to be precise about this, because it is the part people are right to be nervous about. This is escalation with control, not automation running loose.
None of it is on by default. The admin decides, per schedule, whether a follow-up fires and what it does. Sensitive actions like deletion have an approval variant, so a person signs off before anything is removed, and reviewer actions need explicit confirmation. Expiry on its own never deletes anything. It marks the review as unreviewed and triggers whatever the admin configured. Nothing disappears because a deadline passed.
Proof, not percentages
The last thing we changed was what a review leaves behind. We stopped pretending a completion figure meant anything, because it does not. Ninety percent complete tells you ninety percent of people clicked a button. It tells you nothing about what they decided.
So Reviews records two separate things. Status is lifecycle: did the review run. Decision is outcome: what did it conclude. Keeping them apart turns a review from an activity into evidence. It also lets an auditor filter by outcome rather than wade through everything.
There are five decisions, and every workspace in a cycle carries one of them.
Reviewed means the reviewer worked through every step in scope and confirmed the access should stand. The auditor sees who confirmed it and when, not just that a task closed.
Archived means the workspace had served its purpose. The reviewer archived the whole thing rather than confirming access to something nobody needs any more.
Deleted is the strongest outcome, and the one with the most control around it. Delete has an approval variant, so a person signs off before anything is removed.
Rejected means the review landed on somebody who could not fairly judge it, and they said so. That is a valid answer, not a failure, and it is recorded as the outcome rather than expiring in the wrong hands.
Unreviewed is the only outcome nobody wants, and now the only one that is impossible to hide. Expiry marks the review unreviewed and triggers whatever follow-up the admin configured. It never deletes anything on its own.
The first four all carry the status complete. Unreviewed carries the status expired. Each one comes with who acted, when, and a full activity log.
Which means a security leader can now say something defensible in front of an auditor. Access is certified on a recurring cycle. Every workspace carries a decision, not a tick. Ignored reviews escalate rather than disappear. That is repeatable proof, and it is a by-product of the process rather than a project that starts the week the auditor books a meeting.
Why this stopped being a hygiene item
Microsoft’s own deployment blueprint for Microsoft 365 Copilot has three pillars, in this order: remediate oversharing, set up guardrails, meet regulations. Fixing who can reach what comes before everything else. That is Microsoft’s sequencing, not ours.
The volume of content AI can reach keeps growing. In Gartner’s 2026 CIO and Technology Executive Survey, 84% of respondents expect their enterprise to increase generative AI funding this year. Gartner also predicts that by 2028, half of organizations will implement a zero-trust posture for data governance. Certifying who can reach what is the first step of that posture, not the last.
The routes into that content are multiplying too. Verizon’s 2026 Data Breach Investigations Report puts regular workplace AI use at 45% of employees, up from 15%. The permissions did not change. The number of ways to find them did.
Back to that customer
The enterprise I opened with did not need a better dashboard. They needed the people who actually hold the access to spend a few minutes each confirming it, and they needed proof afterwards that it happened. Everything above exists because that turned out to be a design problem rather than a governance problem.
The last thing worth saying is commercial. Reviews is built into the Rencore Teams App you already have, on the same tier entitlement. Nothing extra to buy, and nothing to switch on. This is governance you already pay for, finally closing the loop.
Tiina Rytkönen, who leads product and engineering here, has written about the release from the team’s side, including the four things we left out on purpose, in We rebuilt access reviews around the people who actually have to do them.
Reviews is live
Open the Rencore Teams App and set your first schedule. Start with owners only if that is where you are comfortable. The point is that this time it gets finished.
A note on scope
At general availability Reviews covers four services. Microsoft Teams, reviewed together with its connected SharePoint site, plus standalone SharePoint sites, Viva Engage communities and Microsoft 365 groups. Coverage rolls out service by service, highest permission risk first, with more services following.
Full parity with the previous Access Reviews experience arrives at that experience’s end of life, not at general availability. Reviews starts fresh, so history and configuration do not carry across.
Site access and file access list unique permissions only. Access inherited from the site structure, and files following their folder or library settings, are not shown.
Sources
- Secure and governed data foundation for Microsoft Copilot, Microsoft Learn.
- Gartner press release, 21 January 2026, citing the 2026 Gartner CIO and Technology Executive Survey.
- Verizon Data Breach Investigations Report, 2026.
- The early access customer is anonymized at their request.
Last updated 7 September 2026



.png)
.png)