Reviewer
In identity governance, a reviewer is a person assigned to examine who has access to what and decide whether that access should be kept or removed. Reviewers are the people responsible for approving or revoking access during periodic access reviews. This is a governance responsibility, not a real-time control on whether someone can log in.
A reviewer is a role assigned within an identity governance and administration (IGA) process to make attest-or-revoke decisions during access certification campaigns and access reviews. Reviewers are typically line managers, resource or application owners, or role owners who evaluate whether a subject's granted entitlements, role memberships, or account privileges remain appropriate, often in support of least-privilege and segregation-of-duties objectives. The reviewer function is a lifecycle governance concern that operates on already-provisioned access and does not itself perform runtime enforcement; certification decisions may feed downstream deprovisioning or entitlement changes, but the actual revocation is generally carried out by provisioning workflows rather than by the reviewer directly. Specific reviewer capabilities, delegation options, and campaign scoping vary by IGA vendor and deployment configuration. Note: the general-purpose dictionary and platform sources in the evidence packet describe 'reviewer' in unrelated senses (for example, a critic or a product reviewer) and do not establish the IAM-specific meaning; that meaning is provided here as domain context rather than being drawn from the cited sources.
Why it matters
Access reviews depend on human judgment, and the reviewer is the person exercising that judgment. Automated systems can surface who holds which entitlements, but deciding whether a given grant is still appropriate, whether it reflects current job duties, honors least-privilege intent, or violates segregation-of-duties constraints, typically requires someone with business context. When that responsibility is assigned to the wrong person, or when reviewers rubber-stamp entitlements without genuine scrutiny, the entire certification campaign loses its assurance value even if it completes on schedule.
Reviewers are also central to how organizations demonstrate governance to auditors. Access certification campaigns produce an attestation record showing that a named individual examined specific access and made an attest-or-revoke decision. That record is only as credible as the reviewer's fitness for the task: a line manager who understands a subject's role, a resource owner who knows what an application's entitlements confer, or a role owner accountable for a role definition. Assigning reviewers who lack that context weakens the defensibility of the review, regardless of the tooling behind it.
It is important to keep the reviewer's role in its correct lane. A reviewer operates on already-provisioned access and makes governance decisions; the reviewer does not perform runtime enforcement and generally does not carry out the revocation directly. A revoke decision typically feeds downstream provisioning workflows that execute the change. Conflating the reviewer's attest-or-revoke decision with the act of removing access, or with real-time controls over whether someone can log in, leads to misplaced expectations about how quickly and reliably certification outcomes take effect.
Who it's relevant to
Inside Reviewer
Common questions
Answers to the questions practitioners most commonly ask about Reviewer.