Last Updated on July 28, 2026 by Satyendra
State and local government agencies and educational institutions, collectively known as the state, local, and education (SLED) sector, handle sensitive information, such as criminal justice information, student education records, and health information. Safeguarding data begins with a fundamental question: Does every person with access to data still need it?
Controlling access is not a one-time task. Access attestation is how organizations periodically address that question. It is a recurring review in which department heads verify which users have access to a system or dataset and whether that access is still appropriate. Job responsibilities can change. Individuals can move between departments. Contractors can be added or removed. This is where SLED access attestation becomes an important part of access governance.
This guide covers what SLED access attestation involves, why it matters, how the process works step by step, and what separates a program that genuinely reduces risk from one that’s merely paperwork.
What is a SLED Access Attestation?
SLED access attestation is the formal confirmation resulting from an access review or certification process in which designated reviewers, such as department leads, data owners, system owners, or application owners, verify whether users’ access to systems, applications, files, and sensitive information remains appropriate. It is a recurring process, rather than a one-time clean-up effort, and its focus is on access environments typical of state and local government agencies and educational institutions.
When a department lead completes an attestation, they are typically certifying four things:
- The people listed still work in the relevant team or department.
- Their access supports a legitimate, current business need.
- Their permission levels are appropriate for their current responsibilities.
- Former employees and unnecessary accounts have been identified and, where appropriate, removed or disabled.
IT, security, identity governance, and system administration teams typically collect access information, present it to reviewers, coordinate or implement approved changes, and retain evidence that remediation was completed.
Department leads and business owners provide the business context. They understand employees’ current responsibilities and can determine whether access is still required for someone to perform their job.
Simply acknowledging a spreadsheet of usernames does not constitute an effective access attestation. A productive review involves having all changes approved and implemented, with documentation maintained as evidence. Without such documentation, the review becomes a paperwork exercise and may create a false sense of security.
Why SLED Organizations Need Regular Access Reviews
1. SLED Environments Hold Particularly Sensitive Data
SLED organizations maintain highly sensitive data that, if it falls into unauthorized hands, could pose major threats to security, privacy, and regulatory compliance. Examples include criminal justice information, student and education records, and employee and financial records. Without regular user access reviews, organizations can accumulate permissions that no longer reflect current business needs.
2. Compliance and Audit Requirements
Regular access reviews can help organizations demonstrate that access to sensitive information is being actively governed. Depending on the organization, the information it handles, and its legal or contractual obligations, applicable requirements may include the CJIS Security Policy for criminal justice information, HIPAA and other healthcare requirements for protected health information, FERPA for education records, state privacy and cybersecurity laws, and internal security policies. Access attestations on their own will not suffice for compliance with these regulations.
3. The Security Risks of Unchecked Access
When access is not regularly reviewed, several risks can develop:
- Privilege creep can occur when employees get new roles or additional responsibilities, and yet retain their old permissions
- Inactive or “ghost” accounts may remain enabled long after a person leaves or is no longer associated with an organization.
- Excessive group memberships can give users access to resources they no longer need.
- Complex permission structures can make it difficult to determine effective access because permissions may be inherited through groups or other relationships.
- Shared folders or repositories may be accessible to far more people than necessary.
- Vendor or contractor access that remains active beyond the duration or scope of the engagement for which it was created.
Any of these issues can go unnoticed for months or years in an environment without regular review cycles.
How the Access Attestation Process Works
- Define the Scope: The first step is to identify which departments, systems, repositories, and data types will be included in the review. Not every review needs to cover everything at once. Many organizations prioritize privileged accounts and access to the most sensitive data first, then expand from there. Set a clear review period and completion deadline so the process doesn’t stretch on indefinitely.
- Collect Access and Identity Information: Once the scope is defined, IT and security teams need to gather relevant identity and access information. This should include active and inactive accounts, employment or affiliation status, roles, direct and group-based permissions, privileged access, inherited permissions, and relevant external or guest accounts.
The Lepide Data Security Platform facilitates visibility across file servers, Microsoft 365, Active Directory, and Microsoft Entra ID. Organizations may use its data access governance features to better identify who has access to sensitive data and the permission relationships that provide that access. - Assign Reviews to the Appropriate Department Leads: Each access list must be assigned to a person who understands the users’ current responsibilities. Instead of being forced to interpret complex technical role titles, layered group structures, or raw access control lists, reviewers should be provided with sufficient context to make an informed decision. Meaningful context about the user’s identity and department, the resources they can access, how the access was obtained, and whether the access is privileged should all be included in the review.
- Review Each User’s Access: Reviewers typically have several options for each user, including reducing access, revoking access, approving access when appropriate, and escalating for additional investigation. Unresolved access issues can be prevented from becoming permanent without notice by incorporating a formal exception mechanism instead of allowing ambiguous instances to default to “approve”.
- Remediate Inappropriate Access: An access attestation is only effective when review decisions result in appropriate action. In this stage, reviewer decisions are translated into actionable IT tasks, prioritizing privileged accounts, terminated users, and access to regulated data.
Lepide can help identify excessive permissions by analyzing effective permissions and user activity, highlighting access that may be broader than necessary. Its least-privilege capabilities can support delegated remediation decisions and enable unnecessary permissions to be removed manually or automatically, depending on the organization’s configured policies and workflow. - Preserve Evidence and Continue Monitoring: Retain completed remedial action records, reviewer decisions, and recorded exceptions for future audits. Create reports that make it evident what was examined, decided upon, and altered.
Lepide Data Security Platform supports this with centralized auditing, scheduled reporting, and real-time alerts for permission changes, privilege escalation, and anomalous access behavior across supported data sources. These features help transform attestation from a periodic snapshot into a more continuous process.
Common Access Attestation Challenges in SLED Organizations
- Incomplete or Fragmented Access Data: Access information is often distributed across directories, file systems, cloud services, and applications. Native tools may provide direct, inherited, group-based, or effective access information for individual platforms, but they may not provide a single, consolidated view across the organization’s entire environment. As a result, IT teams and department heads may find it challenging to determine who can truly access critical data.
- Department Leads Lack Useful Context: Managers may receive large spreadsheets containing usernames, group memberships, and technical permissions. In the absence of business context, reviewers can find it difficult to decide if access is warranted. This may result in “rubber-stamp” approvals, in which access is approved simply because the reviewer is unaware of what the permission allows.
- Limited Staff and Budget: IT teams in the public sector sometimes lack the personnel necessary to perform comprehensive manual assessments in every department. Manual access reviews across several systems and departments can be time-consuming. IT teams may find it difficult to finish all remediation work even after excessive access has been discovered.
- Complex Employee and Vendor Lifecycles: The question of who truly owns an access decision is complicated by contractors, seasonal employees, substitute teachers, and individuals who work across multiple agencies. Temporary access can create additional risk if it has no set expiration date and remains active after it is no longer neede
- Point-In-Time Reviews Miss Changes Between Cycles: When roles change and new access is granted, a quarterly certification review that was correct on the day it was completed may become out of date in a matter of days. These gaps remain undetected until the following formal cycle in the absence of ongoing visibility and alerting. For this reason, organizations should combine ongoing monitoring of privileges, group memberships, and permissions with periodic access certification.
Common Mistakes SLED Organizations Make During Access Attestation
While many organizations understand the importance of assessing user access, it can be challenging to provide context for those assessments. Too often, access attestations become a compliance exercise in which managers approve long user lists without having enough information to make informed decisions. As a result, the organizations gain nothing from the review itself, vulnerabilities are missed, and unnecessary access is preserved.
- Focus on Assigned Permissions Instead of Effective Access: A user’s real access differs greatly from what is seen. Permissions can originate from Microsoft 365 roles, nested groups, inherited folder permissions, and numerous Active Directory or Entra ID groups. Looking only at direct permissions rarely tells the whole story. Managers must be aware of what a user may truly access, not merely how that access was granted. Without that visibility, it’s easy to approve permissions that are far broader than intended.
- Asking IT to Decide Who Needs Access: IT Teams are aware of how access is configured up, but they may not always know if it is justified. Questions like “ Does this employee still need access to payroll?” or “Should this contractor still be able to view these case files?” can only be answered by those in charge of a department or who own the data.
The strongest access review processes split these responsibilities clearly. Business owners determine if access is still appropriate after IT collects the data and makes authorized changes. - Turning the Review into a Tick-Box Exercise: It’s likely that a manager will approve most of a spreadsheet including hundreds of users, security groups, and technical authorization names in order to complete the assignment. Reviewers can make well-informed conclusions with the help of a relevant access review. This includes the user’s role, the data they have access to, the last time they used it, and the reason the access was initially authorized.
Reviewers are more likely to identify access that is no longer logical if the information is easier to grasp. - Forgetting about Contractors and Service Accounts: Access reviews often concentrate on employees, but many environments also contain contractor accounts, third-party vendors, service accounts and other non-human identities. These accounts can remain active for months, or even years after they were last needed.
Every review should include these accounts, especially if they have privileged access or can reach sensitive systems and data. - Assuming the Job is Done Once the Review is Complete: An approved review doesn’t reduce risk on its own. The real value comes from acting on the decisions that were made. If a manager requests that access can be taken away, someone must make the necessary changes and verify that they have been made.
During an audit, having a record of both the decision and completed remediation is significantly more reliable than a signed-off spreadsheet by itself. - Waiting Until the Next Review to Find New Risks: Access changes constantly. Teams change, projects start and finish, new groups are formed, and permissions are given to solve immediate problems. A quarterly or annual review only captures what the environment looked like on that particular day.
For this reason, a lot of organizations are switching to continuous access governance instead of periodic access certification. While regular evaluations are still crucial, they are far more successful when they are accompanied by continuous monitoring of group memberships, privileged access, and authorization modifications throughout the year.
Best Practices and Checklist for Effective SLED Access Attestations
SLED Access Attestations Best Practices
By using these recommended strategies, SLED organizations can enhance their access governance initiatives:
- Focus on High-Risk Access First: Prioritize privileged accounts and access to sensitive or regulated data before expanding reviews to lower-risk systems
- Review Effective Access: Don’t limit reviews to direct permissions. Consider inheritance, nested groups, group memberships, and other access routes.
- Give Reviewers Meaningful Context: Provide department heads with clear explanations of duties and resources so they can make well-informed choices.
- Use Activity as Supporting Evidence: Recent access activity can help reviewers understand how permissions are being used. However, inactivity should not automatically be interpreted as proof that access is unnecessary
- Separate Review and Remediation Responsibilities: The person approving access should ideally not be the same person implementing the technical changes.
- Require Time-Bound Exceptions: Every exception should have a business justification, an owner, and an expiration date.
- Escalate Overdue Reviews: Establish clear escalation procedures when department leads fail to complete certifications on time.
- Verify Remediation: Don’t consider the manager’s approval or revocation decision to be the final step. Verify whether the requested access changes were implemented.
- Monitor Between Review Cycles: Combine periodic access certification with continuous permission monitoring.
SLED Access Attestation Checklist
Use this checklist to structure your next access certification:
- Scope and systems documented
- Sensitive data identified
- Reviewers and owners assigned
- Effective permissions collected
- Privileged, stale, and vendor accounts highlighted
- Business justification confirmed
- Decisions recorded
- Exceptions given owners and expiry dates
- Remediation completed and verified
- Evidence retained for auditors
- Continuous monitoring enabled
- Next review scheduled
What SLED Organizations Should Expect from Their Software Vendors
When evaluating tools to support access governance, SLED organizations should generally look for:
- Clear role-based access controls.
- Reports containing users, roles, permissions, and recent activity.
- Export options in formats suitable for audit and reporting purposes.
- Integration with identity and access management systems.
- Integration with provisioning and deprovisioning processes
- Logs showing administrative and permission changes.
- Support for least-privilege configurations
- Documentation that helps teams respond to audits.
- A defined process for reviewing the vendor’s own support and administrative access.
How Lepide Supports Stronger SLED Access Governance
Lepide Data Security Platform can assist SLED organizations in determining who has access to sensitive data, understanding effective permissions and how they were granted, identifying potentially excessive access, involving appropriate business owners in remediation decisions, and maintaining a more auditable least-privilege posture.
- See Who Has Access to Sensitive Information: Lepide helps discover and classify sensitive information, then connects it with relevant permission data, allowing teams to examine effective access by user, object, or resource rather than working from disconnected permission lists.
- Identify Excessive and Risky Permissions: Users may accumulate permissions through group memberships, role changes, or inherited access. Lepide can assist security teams in prioritizing reviews by identifying people whose access appears broader than necessary and by providing permission and activity context.
- Involve Department Leads in Remediation: Rather than leaving business-context decisions entirely to IT, Lepide enables business owners to participate in deciding whether access is justified, reducing the gap between who understands the technical permissions and those who understand the business needs.
- Track Permission Changes Continuously: Lepide monitors changes to group memberships and permissions and can alert teams to configured or detected risk conditions, including privilege escalation, unusual access patterns, and significant permission changes across supported systems. This makes it possible for security teams to look into notable changes in access between formal review cycles.
- Strengthen Audit Evidence: Lepide facilitates reporting on identities, permissions, and activity while assisting with visibility across Active Directory, Microsoft Entra ID, file servers, and Microsoft 365. This supports larger security and compliance projects while helping organizations preserve documentation of access decisions and remediation.
Schedule a demo to discover how Lepide Data Security Platform can help your organization detect and address excessive access while streamlining access reviews.
Conclusion: Move from Periodic Sign-off to Continuous Access Governance
Department leads give the business context required to assess if access is still warranted. IT and security teams provide the technical insight required to understand appropriate permissions and carry out modifications.
A strong SLED access attestation program integrates least-privilege controls, documented remediation, accurate access visibility, effective permission analysis, and ongoing monitoring with business responsibility.