Access Governance Score Calculator
Score access governance maturity from review completion, certification coverage, SoD violations, orphans and exceptions.
Inputs
Access Governance Score
71/ 100
Rating
C — Fair
Weakest Domain
Open policy exceptions
SoD Violation Rate
0.059%
Orphan Account Rate
1.75%
Audit Ready
No
Step by step
Values used
Access reviews completed on time = 88 %; Entitlements covered by certification = 74 %; Open separation-of-duties violations = 26 violations; Entitlements under management = 44,000 entitlements; Orphan accounts = 210 accounts; Identities under management = 12,000 identities; Open policy exceptions = 35 exceptions; Provisioning and revocation automated = 60 %
Access Governance Score
score = 25% review completion + 20% certification coverage + 20% SoD cleanliness + 15% orphan cleanliness + 10% exception hygiene + 10% automation.
Underlying rates
SoD violation rate = open violations ÷ entitlements under management; orphan rate = orphan accounts ÷ identities.
Access Governance Score
= 71 / 100
Rating
= C — Fair
Weakest Domain
= Open policy exceptions
SoD Violation Rate
= 0.059
Orphan Account Rate
= 1.75
Audit Ready
= No
How it works
The six domains are the ones auditors sample, weighted by how much assurance each provides. Rates rather than raw counts keep the score comparable between organisations, and the SoD term is deliberately steep because a small number of toxic combinations is a material finding regardless of estate size. The weakest-domain output is the useful half: a composite score tells you where you stand, but the weakest domain tells you what the next audit will actually flag.
Formulas
Access Governance Score
score = 25% review completion + 20% certification coverage + 20% SoD cleanliness + 15% orphan cleanliness + 10% exception hygiene + 10% automation.
- review completion
- Share of certification items decided inside the campaign window
- certification coverage
- Entitlements that are in scope for any review at all
- SoD cleanliness
- 100 minus 500 × the violation rate, so a 0.2% rate costs all of it
Underlying rates
SoD violation rate = open violations ÷ entitlements under management; orphan rate = orphan accounts ÷ identities.
- separation of duties
- A single identity holding two entitlements that must never be combined, such as raising and approving the same payment
Frequently Asked Questions
How is Access Governance Score calculated?
score = 25% review completion + 20% certification coverage + 20% SoD cleanliness + 15% orphan cleanliness + 10% exception hygiene + 10% automation. The six domains are the ones auditors sample, weighted by how much assurance each provides. Rates rather than raw counts keep the score comparable between organisations, and the SoD term is deliberately steep because a small number of toxic combinations is a material finding regardless of estate size.
Why does Access Governance Score matter?
The weakest-domain output is the useful half: a composite score tells you where you stand, but the weakest domain tells you what the next audit will actually flag.
What values do I need to enter?
This calculator takes 8 inputs: Access reviews completed on time, Entitlements covered by certification, Open separation-of-duties violations, Entitlements under management, Orphan accounts, Identities under management, Open policy exceptions, Provisioning and revocation automated. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
What is a separation-of-duties violation?
It is one identity holding two entitlements that policy says must be split — creating a vendor and approving its payments, writing code and deploying it to production, or requesting and granting privileged access. They accumulate mostly through role changes where the old access was never revoked.
Why weight review completion the highest?
Because it is the control auditors test first and the one most easily faked. A campaign that closes at 88% has 12% of its decisions unmade, and the entitlements behind them stay live by default — so incomplete reviews are worse than no review, since they carry an assurance claim that is not true.
You might also need
- IAM Health Score CalculatorCommonly used together
- Permission Coverage CalculatorCommonly used together
- Access Review CalculatorCommonly used together
- RBAC Role Count CalculatorCommonly used together
- JWT Payload Size CalculatorAlso in Identity & Access Management
- Identity Risk CalculatorAlso in Identity & Access Management