jump to content

Run an Access Review Campaign

Follow the entire console workflow for an access review campaign, from creating and running it to reviewing accounts, applying flags, and recording decisions.

Show as Markdown

An access review campaign takes a timely instant view of the accounts available from one or more access sources.Reviewer can then mark accounts, record a decision for each entry, and keep the review completed.

Before you start, create at least one access source. Connector Directory, or create a CSV source.

  1. In the platform, open the organization and go to Access Reviews > Campaigns.
  2. Click New campaign.
  3. Enter a Name and, optionally, a Description.
  4. Select the sources that belong to the review, then click Create.

The campaign starts in DraftOpen it to add another source before it starts. A campaign must contain at least one source.

Review the source list, then click Start campaignThe platform waits a queue for each source and changes the state of the campaign to In progress.

Each source shows the recovery status and number of returned accounts:

  • Queued or Fetching means collection is still running.
  • Success This means that the source snapshot is ready.
  • Failed Solve the source or credential issue before relying on the campaign.

After the collection is completed, the campaign Pending actionsThe start of the campaign determines its scope: you can’t add or remove sources after this point.

Depending on what the provider exposes, the platform displays your name, email address, role, administrator status, account status, MFA status, and last login.

For each account:

  1. Check your identity, assigned role, administrative access, status, MFA, and recent activity.
  2. Add any useful flags Describe what you found.
  3. Record one of these decisions:
    • ApproveAccesul actual este adecvat.
    • RevokeAccesul trebuie eliminat.
    • ModifyThe account should remain, but access to it should change.
    • Escalate: another reviewer or owner must decide.

Revoke, modify and escalate requires a note explaining the decision.You can select multiple accounts to apply a decision or bulk flags.

Flags are optional tags that reviewers attach to an account during a campaign. They do not replace a decision: each entry still needs approval, revocation, modification or escalation before the campaign can be completed.

You can set flags on a single account or apply them bulk to a selection.

Flag Use when
Orphan account The account does not have a clear owner or is no longer mapped to a known person in the organization.
Dormant The account appears unused for a long period of time in relation to your review policy.
Terminated user The person has left the organization and the account should no longer have access.
Contractor expired The employment of a contractor or temporary worker has ended, but the account remains.
Flag Use when
Excessive privileges The account has more access than the role or job requires.
SoD conflict The account combines the tasks that your task segregation policy separates.
Privileged access The account holds high or administrative rights that deserve explicit examination.
Role creep Access has accumulated over time beyond what the current role needs.
Flag Use when
No justification There is no clear business reason for the account or access level.
Out of department The account belongs outside the team or department that should own this system.
Shared account More than one person uses the same login or the account is shared in another way.

The platform does not automatically detect them from the provider’s data; choose them based on what the instant image shows and the internal context.

The Complete campaign The action becomes available after each entry has a decision.

  1. Confirm that no entries remain pending.
  2. It confirms that failed recovery sources have been investigated.
  3. Click Complete campaign, then confirm.

Completion finalises decisions and changes the state of the campaign Completed. This action cannot be undone.

stateDiagram-v2
  state "Draft" as draft
  state "In progress" as inProgress
  state "Pending actions" as pending
  state "Completed" as completed
  state "Cancelled" as cancelled

  [*] --> draft: Create campaign with sources
  draft --> inProgress: Start campaign
  inProgress --> pending: Source fetches finish
  pending --> completed: Every entry has a decision
  draft --> cancelled: Cancel through API or CLI
  pending --> cancelled: Cancel through API or CLI
  completed --> [*]
Sources can be added while a campaign is a project; the scope is fixed once it starts.
Status Meaning
Draft Sources can still be added, and the campaign has not taken over accounts.
In progress The platform collects accounts from selected sources.
Pending actions The collection is finished and the entries are ready for decisions.
Completed Each entry has a final decision and the campaign is closed.
Cancelled The campaign has been cancelled via API or CLI and is no longer active.

The console can delete any campaign that is not In progressDeleting permanently removes the campaign, so don’t use it as a replacement for completing a review that needs to be kept as evidence.

Pentru automatizare, vezi CLI access-review commands.

Ultima actualizare: