Inbox Triage
You're the access reviewer. A stream of access requests and security alerts hits your queue — approve, deny, or escalate each one. Not every request is suspicious, but the ones you rubber-stamp could expose the entire organization.
Ready to play?
Put your awareness to the test. See if you can spot the threats before it's too late.
Launch GameWhy This Matters
Access review fatigue is a documented phenomenon in identity governance. When reviewers face hundreds of access decisions per cycle, approval rates climb above 95% — not because 95% of access is appropriate, but because reviewers stop reading. A 2026 Sailpoint study found that the average access reviewer spends less than 8 seconds per decision.
Attackers exploit this. Requests for excessive permissions are timed to coincide with busy review periods. Compromised accounts request additional access knowing reviewers will approve by default. Social engineering targets the approval chain, not the system.
The cost of a wrong approval is asymmetric: approving dangerous access can lead to data breaches, compliance violations, and regulatory fines. Denying a legitimate request causes a brief inconvenience and a follow-up conversation. Yet most organizations optimize for speed over accuracy, treating access reviews as checkbox compliance rather than active defense.
What You'll Learn
Evaluate access requests against role appropriateness and least-privilege principles
Recognize when a request should be escalated rather than approved or denied outright
Understand the asymmetric risk of rubber-stamping approvals versus over-denying
Practice balancing operational efficiency with security in access review workflows