Skip to content

About Access Reviews

The access review part of a certification is when someone who is an authority of some sort – such as a people manager, or someone responsible for an application like a Human Resources system or a financial database – reviews the access that other users have, to verify whether or not it is correct and appropriate, and to make any necessary corrections to revoke inappropriate access.

Customization of Access Reviews

IdentityIQ provides many ways to customization certifications and the access reviews that comprise them. These options control things like the actions a reviewer can take to correct an action, whether or not reviewers can process access decisions in bulk or only one by one, whether reviewers can delegate reviews to other people, et cetera. Since many access review options can be enabled or disabled when the certification is set up, reviewers may see only some of the features and options described in this section in their own access reviews.

Here are some examples of the customization options for access reviews that can be set by the person who creates the certification:

  • Requiring an electronic signature to close an access review

  • Requiring comments when an access item is approved

  • Enabling or disabling the option to delegate a review

  • Limiting the number of times a review can be reassigned

  • Enabling an exception period, to allow a user to retain access for a certain time period but no longer

  • Allowing items to approved, revoked, or reassigned in bulk, versus item-by-item only

How Reviewers Are Notified About Access Reviews

Certifications can be configured to send an email notification to reviewers when the access reviews are available. An Access Review tile on the reviewer's home page also shows a count of how many reviews are awaiting the user's attention.

Whether or email notifications are sent, the access reviews themselves appear in the IdentityIQ user interface for the assigned reviewers, and can be accessed from these page or menu option paths:

  • In the top navigation menu of IdentityIQ, click the My Work > My Access Reviews menu option.

  • In the Quicklinks (left sidebar) menu, click the My Tasks > Access Reviews option.

  • On the home page, click the Access Reviews tile.

How Access Review Items are Displayed: Important, Open, and Review Tabs

The items for you to review are presented in a tabbed interface.

Important

The Important tab lists the access review items that require immediate attention. This includes policy violations, challenge items, and returned items. (Challenge items are items which the certifier revoked and the access holder has challenged the decision. Returned items are items which have been delegated to someone else for input and have been rejected by that user and sent back to the certifier.) The Important tab appears only when any of your review items fall into the "important" category.

Note

If you do not have any review items that fall in the "Important" category, this tab will not appear in your Access Review listing. That means that some of your access reviews may show you an Important tab, and others may not.

Open

The Open tab shows access review items awaiting your attention, excluding any items listed on the Important tab.

Review

The Review tab shows the access review items that you have completed for this certification. You can change decisions from this tab up until the point the access review has been completed and signed off.