We rebuilt access reviews around the people who actually have to do them

Reviews is in the Rencore Teams App from today, on the tier entitlement you already have. Nothing extra to buy, and nothing to switch on. Here is what my team built fresh, and the four things we left out on purpose.
Reviews is live in the Rencore Teams App from today. It is a big release for my team, and the one I most wanted us to get right.
We had a working access review before this. The straightforward move was to lift it into Microsoft Teams as it stood, screen for screen. We did not take it. We rebuilt the review around the person who has to complete it, and almost every decision below follows from that.
The reason came out of early access. One customer, a large enterprise ten years into SharePoint, could not say what had been shared with “Everyone”. For a decade that sat on a list as a hygiene item. Then their Microsoft 365 Copilot rollout turned the same content into answers, and a dormant permission became a search result. They knew they should review access. They had tried. The reviews never finished.
We gave the team one goal. A workspace owner with no governance knowledge should be able to complete a review correctly, in a few clicks, with no training.
The brief was cognitive load, not features
Every design argument got settled against that one sentence. It is why Reviews runs inside Microsoft Teams on Fluent UI. Fluent UI is the design language of Teams, so the controls already behave the way a reviewer expects. There is no separate tool, no extra login, and nothing to learn before the control can work.
It is also why the app is organized by the job rather than by the data. Pending work is one click away. Organizing by object, filter, and property is right for a governance specialist and wrong for everybody else, and the reviewer is everybody else.
Three things we built fresh
Scope the administrator sets, so a review can start. Owners are always confirmed. Members with guests, visitors, site access, and file access are each optional. An admin picks the scope they are ready to defend and grows it cycle on cycle. An owners-only schedule gives the reviewer one step and a summary.
A guided task with six steps. Owners first, then members with guests listed inline, then visitors, then site access, then file access, then the summary. In the people steps each row carries a name, a job title, and a role, and nothing else. There is one action per row, Remove, which flips to Undo. Leaving a row alone is how a reviewer confirms it, and owners and members can be added as well as removed. Every removal is reversible until they submit. The instructions at the top of the task are written by the customer’s own IT team, in their own words. A workspace can carry more than one reviewer, and the review resumes where the last person left it.

Follow-up when a review is ignored. An expired review used to look identical to a completed one, so ignoring one cost nothing. Now expiry marks the review unreviewed and triggers whatever the administrator configured. None of it is on by default. It is set per schedule. Sensitive actions such as deletion have an approval variant, so a person signs off before anything is removed. Expiry on its own never deletes anything.
Tobias Tiehmann, the Product Manager for Reviews, has written up the reviewer research behind those three decisions in The person doing your access review has never heard of governance.
Four things we left out on purpose
The list of what we left out decided as much as the feature list did.
No risk score next to a person’s name. A people row shows a name, a job title, and a role. Site access adds a permission level. File access adds who a file is shared with. We could have scored every row. A team lead cannot check a score, so scoring would move the decision from a person who knows the team to a number nobody owns.
No Keep button. Every button is a decision, and decisions are what stall a review. Leaving a row alone confirms it, so a workspace with nothing to change takes seconds.
No completion percentage as the result. Reviews records two separate fields. Status is the lifecycle of the review. Decision is the outcome for the workspace: unreviewed by default, then reviewed, archived, deleted, rejected, or a custom action the administrator has named. Ninety per cent complete tells you that people clicked. It does not tell you what they concluded, and that is the question an auditor asks.
No optional comment. A reviewer has to write a comment for the administrator before a review completes, and Submit stays disabled until they do. It is one more thing to type and we kept it, because a decision with no reason attached is not evidence.
Governance stops sitting with two people
One or two administrators can only ever stretch to some of the topics. No feature raises that ceiling, because the constraint is people rather than software. Taking the whole organization on board, so that governance is shared, is what changes the outcome.
That is what Reviews is built for. The people who hold the access make the call, in the app they already have open. The platform records what they decided, and chases what they ignore.
Why we shipped it now
Microsoft’s own deployment blueprint for Microsoft 365 Copilot sets out three pillars in order: remediate oversharing, set up guardrails, meet regulations. Fixing who can reach what comes first. That is Microsoft’s sequencing, not ours.
The amount of content AI can reach keeps growing. In Gartner’s 2026 CIO and Technology Executive Survey, 84% of respondents expect their enterprise to increase generative AI funding this year. Gartner also predicts that by 2028, half of organizations will implement a zero-trust posture for data governance. Certifying who can reach what is the first step of that posture.
The ways into that content are multiplying too. Verizon’s 2026 Data Breach Investigations Report puts regular workplace AI use at 45% of employees, up from 15%. Those permissions were set years ago. What changed is how easily they can now be reached.
Reviews is live in your Rencore Teams App

Open it and set your first schedule. Owners only is a good first cycle, and you can widen the scope once you have seen what comes back. Reviews is part of the Rencore Teams App, on the tier entitlement you already have. There is nothing extra to buy, and nothing to switch on.
A note on scope
At general availability Reviews covers four services. Microsoft Teams, reviewed together with its connected SharePoint site, plus standalone SharePoint sites, Viva Engage communities, and Microsoft 365 groups. Coverage rolls out service by service, highest permission risk first, with more services following. Full parity with the previous Access Reviews experience arrives at that experience’s end of life, not at general availability. Reviews starts fresh, so history and configuration do not carry across. Site access and file access list unique permissions only. Access inherited from the site structure, and files following their folder or library settings, are not shown.
Sources
- Microsoft 365 Copilot blueprint for oversharing, Microsoft Learn.
- Gartner press release, 21 January 2026, citing the 2026 Gartner CIO and Technology Executive Survey.
- Verizon Data Breach Investigations Report, 2026.
- The early access customer is anonymized at their request.
Last updated 7 September 2026



.png)
.png)