Start free trial
Collaboration Governance

We rebuilt access reviews around the people who actually have to do them

We rebuilt access reviews around the people who actually have to do them

Reviews is in the Rencore Teams App from today, on the tier entitlement you already have. Nothing extra to buy, and nothing to switch on. Here is what my team built fresh, and the four things we left out on purpose.

Reviews is live in the Rencore Teams App from today. It is a big release for my team, and the one I most wanted us to get right.

We had a working access review before this. The straightforward move was to lift it into Microsoft Teams as it stood, screen for screen. We did not take it. We rebuilt the review around the person who has to complete it, and almost every decision below follows from that.

The reason came out of early access. One customer, a large enterprise ten years into SharePoint, could not say what had been shared with “Everyone”. For a decade that sat on a list as a hygiene item. Then their Microsoft 365 Copilot rollout turned the same content into answers, and a dormant permission became a search result. They knew they should review access. They had tried. The reviews never finished.

We gave the team one goal. A workspace owner with no governance knowledge should be able to complete a review correctly, in a few clicks, with no training.

The brief was cognitive load, not features

Every design argument got settled against that one sentence. It is why Reviews runs inside Microsoft Teams on Fluent UI. Fluent UI is the design language of Teams, so the controls already behave the way a reviewer expects. There is no separate tool, no extra login, and nothing to learn before the control can work.

It is also why the app is organized by the job rather than by the data. Pending work is one click away. Organizing by object, filter, and property is right for a governance specialist and wrong for everybody else, and the reviewer is everybody else.

Three things we built fresh

Scope the administrator sets, so a review can start. Owners are always confirmed. Members with guests, visitors, site access, and file access are each optional. An admin picks the scope they are ready to defend and grows it cycle on cycle. An owners-only schedule gives the reviewer one step and a summary.

A guided task with six steps. Owners first, then members with guests listed inline, then visitors, then site access, then file access, then the summary. In the people steps each row carries a name, a job title, and a role, and nothing else. There is one action per row, Remove, which flips to Undo. Leaving a row alone is how a reviewer confirms it, and owners and members can be added as well as removed. Every removal is reversible until they submit. The instructions at the top of the task are written by the customer’s own IT team, in their own words. A workspace can carry more than one reviewer, and the review resumes where the last person left it.

Step 1 of 6 in a Rencore review: the Owners step listing each owner by name, job title and role, with a Remove button on every row and no Keep button.

Follow-up when a review is ignored. An expired review used to look identical to a completed one, so ignoring one cost nothing. Now expiry marks the review unreviewed and triggers whatever the administrator configured. None of it is on by default. It is set per schedule. Sensitive actions such as deletion have an approval variant, so a person signs off before anything is removed. Expiry on its own never deletes anything.

Tobias Tiehmann, the Product Manager for Reviews, has written up the reviewer research behind those three decisions in The person doing your access review has never heard of governance.

Four things we left out on purpose

The list of what we left out decided as much as the feature list did.

No risk score next to a person’s name. A people row shows a name, a job title, and a role. Site access adds a permission level. File access adds who a file is shared with. We could have scored every row. A team lead cannot check a score, so scoring would move the decision from a person who knows the team to a number nobody owns.

No Keep button. Every button is a decision, and decisions are what stall a review. Leaving a row alone confirms it, so a workspace with nothing to change takes seconds.

No completion percentage as the result. Reviews records two separate fields. Status is the lifecycle of the review. Decision is the outcome for the workspace: unreviewed by default, then reviewed, archived, deleted, rejected, or a custom action the administrator has named. Ninety per cent complete tells you that people clicked. It does not tell you what they concluded, and that is the question an auditor asks.

No optional comment. A reviewer has to write a comment for the administrator before a review completes, and Submit stays disabled until they do. It is one more thing to type and we kept it, because a decision with no reason attached is not evidence.

Governance stops sitting with two people

One or two administrators can only ever stretch to some of the topics. No feature raises that ceiling, because the constraint is people rather than software. Taking the whole organization on board, so that governance is shared, is what changes the outcome.

That is what Reviews is built for. The people who hold the access make the call, in the app they already have open. The platform records what they decided, and chases what they ignore.

Why we shipped it now

Microsoft’s own deployment blueprint for Microsoft 365 Copilot sets out three pillars in order: remediate oversharing, set up guardrails, meet regulations. Fixing who can reach what comes first. That is Microsoft’s sequencing, not ours.

The amount of content AI can reach keeps growing. In Gartner’s 2026 CIO and Technology Executive Survey, 84% of respondents expect their enterprise to increase generative AI funding this year. Gartner also predicts that by 2028, half of organizations will implement a zero-trust posture for data governance. Certifying who can reach what is the first step of that posture.

The ways into that content are multiplying too. Verizon’s 2026 Data Breach Investigations Report puts regular workplace AI use at 45% of employees, up from 15%. Those permissions were set years ago. What changed is how easily they can now be reached.

Reviews is live in your Rencore Teams App

The Reviews tab in the Rencore Teams App, listing four active team reviews with their type, assigned reviewers and due date.

Open it and set your first schedule. Owners only is a good first cycle, and you can widen the scope once you have seen what comes back. Reviews is part of the Rencore Teams App, on the tier entitlement you already have. There is nothing extra to buy, and nothing to switch on.

Set up your first review

A note on scope

At general availability Reviews covers four services. Microsoft Teams, reviewed together with its connected SharePoint site, plus standalone SharePoint sites, Viva Engage communities, and Microsoft 365 groups. Coverage rolls out service by service, highest permission risk first, with more services following. Full parity with the previous Access Reviews experience arrives at that experience’s end of life, not at general availability. Reviews starts fresh, so history and configuration do not carry across. Site access and file access list unique permissions only. Access inherited from the site structure, and files following their folder or library settings, are not shown.

Sources

  • Microsoft 365 Copilot blueprint for oversharing, Microsoft Learn.
  • Gartner press release, 21 January 2026, citing the 2026 Gartner CIO and Technology Executive Survey.
  • Verizon Data Breach Investigations Report, 2026.
  • The early access customer is anonymized at their request.

Common questions on this

Why do access reviews never get finished?
Because the person who has to answer is not a governance specialist. A workspace owner receives a request full of objects, filters and permission levels, with no idea what a correct answer looks like and no time to work it out. A review that a busy owner cannot answer in under a minute does not get answered, it gets approved, or it sits there until it expires. More reminders do not fix that. Fewer decisions per row, plain language, and a scope small enough that the owner can defend every line of it do.
What does a reviewer actually need to see to decide whether someone should keep access?
Three things, which is less than most tools show. A name, a job title, and the role that person holds in this workspace. A team lead recognizes a colleague and knows whether they still belong there, and that judgement is the whole thing you are asking for. A risk score placed next to the name reads as authority the reviewer cannot check, so it moves the call away from the person who knows the team and onto a number nobody owns. For site and file access, add one thing only: the permission level, and who a file is shared with outside the team.
How do you stop reviewers from approving everything without reading it?
Make confirming cheap and the reason mandatory. Keep the scope to what the owner can genuinely speak to, owners only for the first cycle, then widen it once you have seen what comes back. Require a written comment before the review can be submitted, so a decision arrives with a reason attached rather than just a timestamp. And keep every removal reversible until submission, because a reviewer who is afraid of breaking something approves everything rather than removing anything.
What happens to review decisions after the review closes?
That is the part most access review programs lose. A completion percentage tells you that people clicked, not what they concluded, and the conclusion is what an auditor asks for. Record two things separately: the lifecycle status of the review, and the decision for the workspace itself, unreviewed by default, then reviewed, archived, deleted or rejected. Keep the reviewer's written reason with it, because a decision with no reason attached is not evidence. And decide in advance what an expired review means, since if an ignored review looks identical to a finished one, ignoring it costs nothing.
Do Microsoft Entra ID access reviews already cover this?
They cover the identity side well. With Microsoft Entra ID Governance licensing you can recertify membership of groups, access packages and applications, review guest access, and remove it on a schedule. What they do not reach is sharing inside the content itself: a SharePoint site shared with "Everyone", a file link handed to someone outside the group, or the question of whether that workspace is still needed at all. Rencore Reviews covers that second half and runs the review inside Microsoft Teams, extending Entra rather than standing in for it.
Is Reviews something extra to buy, and which services does it cover?
It is part of the Rencore Teams App, on the tier entitlement you already have, so there is nothing extra to buy and nothing to switch on. At general availability it covers four services: Microsoft Teams reviewed together with its connected SharePoint site, plus standalone SharePoint sites, Viva Engage communities and Microsoft 365 groups, with further services following, highest permission risk first. Two limits are worth knowing up front. Site access and file access list unique permissions only, so inherited access is not shown, and Reviews starts fresh, so history and configuration do not carry across.

Last updated 7 September 2026

Related articles

Rencore newsletter

Subscribe to our newsletter

Get the latest Microsoft 365 governance insights delivered to your inbox.

Loading form