Access Reviews Overview
Learn how platform access review connects providers or CSV data as instant sources, identities, and permissions, and records reviewers’ decisions.
Access checks enable an organization to take a timely snapshot of identities and permissions, record reviewers’ decisions, and retain the outcome of the campaign.
How It Works
Posts Tagged ‘how it works’- Create one or more access sources.
- Create a campaign and attach the sources that define its scope.
- Start the campaign to retrieve and capture available access entries.
- Review entries, add flags where it is useful, and records the decisions.
- Complete the campaign after each entry has a decision.
The instant image remains separate from the provider’s live directory, so the remedy in a provider doesn’t silently rewrite the history of decisions.
See Run an Access Review Campaign for the entire console workflow.
What the platform collects
Section entitled “What the platform collects”For each account in a review, the platform displays the following, wherever the provider exposes them.
| Field | What it tells reviewers |
|---|---|
| Name | Name of account holder (service accounts are marked) |
| The account’s email address | |
| Role | The role(s) that the account holds with the provider |
| Admin | Whether the account has administrator access |
| Status | If your account is active or deactivated |
| MFA | Whether multi-factor authentication is enabled |
| Last login | When the last account was connected or used |
Connection Methods
Section entitled “Connection Methods”- OAuth. When Add Source offers Connect for a provider, the platform sends you to the consent screen of that provider. Availability depends on the provider and the platform implementation.
- Client credentials or API keys. Generate a provider credential and insert it into the platform.The type of credentials and permissions required vary, so check Connector Directory.
- CSV. Put a list of exported accounts for a system to which the platform cannot connect directly. Create a CSV Access Source.
Access reviews live under Access Reviews Within your organization: Sources tab connects providers, the Campaigns tab runs reviews.
See How the platform protects integration credentials for encryption, access control and data manipulation.
Review Boundaries
Section “Review Boundaries”Providers'APIs expose different fields and may omit MFA, login, status or role information. A empty value means that the source has not provided it; it should not be interpreted as a passing or failing control.
Registering a decision does not change the account in the provider. Completes withdrawals and role changes in the source system, then uses the campaign record as proof of the review.