jump to content

Access Reviews Overview

Learn how platform access review connects providers or CSV data as instant sources, identities, and permissions, and records reviewers’ decisions.

Show as Markdown

Access checks enable an organization to take a timely snapshot of identities and permissions, record reviewers’ decisions, and retain the outcome of the campaign.

  1. Create one or more access sources.
  2. Create a campaign and attach the sources that define its scope.
  3. Start the campaign to retrieve and capture available access entries.
  4. Review entries, add flags where it is useful, and records the decisions.
  5. Complete the campaign after each entry has a decision.

The instant image remains separate from the provider’s live directory, so the remedy in a provider doesn’t silently rewrite the history of decisions.

See Run an Access Review Campaign for the entire console workflow.

For each account in a review, the platform displays the following, wherever the provider exposes them.

Field What it tells reviewers
Name Name of account holder (service accounts are marked)
Email The account’s email address
Role The role(s) that the account holds with the provider
Admin Whether the account has administrator access
Status If your account is active or deactivated
MFA Whether multi-factor authentication is enabled
Last login When the last account was connected or used
  • OAuth. When Add Source offers Connect for a provider, the platform sends you to the consent screen of that provider. Availability depends on the provider and the platform implementation.
  • Client credentials or API keys. Generate a provider credential and insert it into the platform.The type of credentials and permissions required vary, so check Connector Directory.
  • CSV. Put a list of exported accounts for a system to which the platform cannot connect directly. Create a CSV Access Source.

Access reviews live under Access Reviews Within your organization: Sources tab connects providers, the Campaigns tab runs reviews.

See How the platform protects integration credentials for encryption, access control and data manipulation.

Providers'APIs expose different fields and may omit MFA, login, status or role information. A empty value means that the source has not provided it; it should not be interpreted as a passing or failing control.

Registering a decision does not change the account in the provider. Completes withdrawals and role changes in the source system, then uses the campaign record as proof of the review.

Ultima actualizare: