How Costpoint Access Reviews Work
A typical review begins with an inventory of active users and their assigned roles. Reviewers then examine the permissions associated with each account and compare them with documented responsibilities. Managers, application administrators, finance leaders, or control owners may confirm whether access should remain unchanged, be modified, or be removed.
- User identification: Establish which employees, contractors, service accounts, and administrators have Costpoint access.
- Role evaluation: Review the Costpoint roles and permissions assigned to each account.
- Business-owner validation: Have appropriate managers or control owners confirm that access matches current responsibilities.
- Exception resolution: Document and address permissions that require changes, clarification, or additional approval.
- Evidence retention: Maintain review records showing who reviewed access, what was examined, and what actions resulted.
Access Reviews and Finance Controls
Costpoint access should align with the financial activities a user performs. A person responsible for invoice review may need transaction-processing permissions, while a general ledger administrator may require broader configuration privileges. Reviewers should distinguish these responsibilities rather than treating every finance user as having the same access requirements.
For invoice workflows, reviewers can examine whether users who perform capture, extraction, validation, matching, gl coding, approval, and posting have permissions appropriate to their duties. Access should also support accurate coding against the chart of accounts without granting unnecessary administrative privileges.
Payment activities deserve similar attention. When reviewing users involved in supplier approvals, payment methods, payment timing, or cash outflow, teams can verify whether authorization levels correspond with assigned responsibilities and documented financial controls. This is particularly relevant to vendor payment workflows.
Segregation of Duties and Approval Access
Access reviews can support segregation of duties by examining combinations of permissions that could allow one user to initiate, approve, process, and record the same financial activity. The review should consider actual business responsibilities rather than relying only on job titles.
For example, a procurement employee may need authority to create or review purchasing transactions but should be assessed separately from users responsible for payment authorization. Similar distinctions can apply to journal preparation, approval, posting, and financial reporting.
Specialized access categories should also be documented. Executive Access describes access granted to executives or senior leaders, while Expense System Access concerns permissions within systems used to manage employee expenses and related financial workflows.
Access Reviews Across Costpoint Environments
Costpoint may operate alongside other enterprise applications, making access governance relevant across the broader ERP environment. Organizations should review how users move between systems and whether roles remain aligned when applications are integrated or when employees change responsibilities.
For organizations using deltek Costpoint, access reviews can be coordinated with ERP administration, identity management, and application changes. A user who transfers between departments may require different Costpoint permissions even when the person's underlying identity remains unchanged.
Organizations can also define review procedures for connected applications and specialized access points. A Vendor Portal can give vendors secure access to purchase orders, invoices, and payments while supporting procurement teams with visibility and document collaboration. Such external access should have clearly defined ownership and review criteria.
Payment and User Access Governance
Access reviews should cover users involved in payment execution as well as those who approve payment instructions. For example, Payment Processing By ACH can involve automated file generation, bank-specific format requirements, access controls, and audit trails. Reviewing the users who can initiate, approve, or administer these activities helps maintain clear authorization boundaries.
Payment-related access can also be reviewed alongside financial decision workflows. Early Payments Recommendations can involve early-payment discounts, vendor terms, cost of capital, payment approvals, and timing decisions. Access reviews should establish which users can view recommendations, approve payments, or modify relevant settings.
Monitoring and Review Evidence
Access reviews become more useful when organizations retain evidence showing the scope, reviewer, date, decisions, and resulting changes. Documentation should make it possible to understand why a user retained particular permissions and how exceptions were handled.
System Access Monitoring complements periodic access reviews by providing visibility into authentication and access activity. Monitoring can help organizations identify unusual activity or changes that warrant additional review between scheduled certification cycles.
Review frequency should reflect organizational requirements, user turnover, system sensitivity, and applicable control policies. Privileged accounts and high-impact financial permissions may warrant more frequent attention than ordinary read-only access.
Best Practices for Costpoint Access Reviews
- Maintain an accurate inventory of Costpoint users, roles, privileged accounts, and relevant external access.
- Assign clear ownership for reviewing finance, procurement, project, and administrative permissions.
- Compare permissions with current job responsibilities rather than relying solely on historical role assignments.
- Document approvals, exceptions, remediation actions, and completion dates for each review cycle.
- Coordinate access reviews with employee transfers, onboarding, offboarding, and major ERP changes.
- Use monitoring records and audit evidence to support ongoing access governance between formal review cycles.
Organizations that provide broad user availability should still maintain role-based controls. Unlimited Access describes a model designed to provide broad user availability with automated onboarding, role-based configurations, and continuous availability; access governance remains important when determining what each user can actually perform.
Summary
Costpoint Access Reviews provide a structured way to validate whether users retain appropriate permissions for their current responsibilities. By examining roles, financial duties, approval authority, segregation of duties, external access, payment permissions, and monitoring evidence, organizations can maintain stronger access governance across Costpoint and connected finance workflows.