jump to content

Access Reviews Overview

Learn how the platform access reviews connect providers or CSV data as sources, snapshot identities and permissions, and record reviewer decisions.

View as Markdown

Access reviews let an organization take a point-in-time snapshot of identities and permissions, record reviewer decisions, and preserve the result of the campaign. Sources can be connected providers or CSV data exported from another system.

  1. Create one or more access sources.
  2. Create a campaign and attach the sources that define its scope.
  3. Start the campaign to fetch and snapshot available access entries.
  4. Review entries, add flags where useful, and record decisions.
  5. Complete the campaign after every entry has a decision.

Campaign statistics describe the current review state. The snapshot remains separate from the provider’s live directory, so remediation in a provider does not silently rewrite the decision history.

See Run an Access Review Campaign for the complete console workflow.

For each account in a review, the platform shows the following, wherever the provider exposes it. Fields the provider doesn’t return are left blank.

FieldWhat it tells reviewers
NameThe account holder’s name (service accounts are marked)
EmailThe account’s email address
RoleThe role(s) the account holds in the provider
AdminWhether the account has administrator access
StatusWhether the account is active or disabled
MFAWhether multi-factor authentication is enabled
Last loginWhen the account last signed in or was used
  • OAuth. When Add Source offers Connect for a provider, the platform sends you to that provider’s consent screen. Availability depends on the provider and your the platform deployment.
  • API key or client credentials. You generate a credential on the provider and paste it into the platform. The credential type and required permissions vary, so check the Connector Directory.
  • CSV. Paste an exported account list for a system the platform cannot connect to directly. See Create a CSV Access Source.

Access reviews live under Access Reviews in your organization: the Sources tab connects providers, the Campaigns tab runs reviews.

See How the platform Protects Integration Credentials for encryption, access control, and data handling.

Provider APIs expose different fields and may omit MFA, login, status, or role information. A blank value means the source did not provide it; it should not be interpreted as a passing or failing control. Reviewers remain responsible for deciding whether an identity and its access are appropriate.

Recording a decision does not change the account in the provider. Complete revocations and role changes in the source system, then use the campaign record as evidence of the review.

Ultima actualizare: