Periodic access reviews have long been the default for managing identity risk and maintaining regulatory compliance. These reviews were designed when most identity risks came from human users, who follow the “joiner, mover, leaver” pattern of access changes. Additionally, core business risks and functions were encapsulated within a single business application, allowing reviews to be scoped around individual applications.