Score access governance maturity from review completion, certification coverage, SoD violations, orphans and exceptions.
The six domains are the ones auditors sample, weighted by how much assurance each provides. Rates rather than raw counts keep the score comparable between organisations, and the SoD term is deliberately steep because a small number of toxic combinations is a material finding regardless of estate size. The weakest-domain output is the useful half: a composite score tells you where you stand, but the weakest domain tells you what the next audit will actually flag.
Access Governance Score
score = 25% review completion + 20% certification coverage + 20% SoD cleanliness + 15% orphan cleanliness + 10% exception hygiene + 10% automation.
Underlying rates
SoD violation rate = open violations ÷ entitlements under management; orphan rate = orphan accounts ÷ identities.
score = 25% review completion + 20% certification coverage + 20% SoD cleanliness + 15% orphan cleanliness + 10% exception hygiene + 10% automation. The six domains are the ones auditors sample, weighted by how much assurance each provides. Rates rather than raw counts keep the score comparable between organisations, and the SoD term is deliberately steep because a small number of toxic combinations is a material finding regardless of estate size.
The weakest-domain output is the useful half: a composite score tells you where you stand, but the weakest domain tells you what the next audit will actually flag.
This calculator takes 8 inputs: Access reviews completed on time, Entitlements covered by certification, Open separation-of-duties violations, Entitlements under management, Orphan accounts, Identities under management, Open policy exceptions, Provisioning and revocation automated. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
It is one identity holding two entitlements that policy says must be split — creating a vendor and approving its payments, writing code and deploying it to production, or requesting and granting privileged access. They accumulate mostly through role changes where the old access was never revoked.
Because it is the control auditors test first and the one most easily faked. A campaign that closes at 88% has 12% of its decisions unmade, and the entitlements behind them stay live by default — so incomplete reviews are worse than no review, since they carry an assurance claim that is not true.