Access reviews
Reviews that close. Evidence that exports.
Review campaigns scoped to what matters. Reviewers see only what’s theirs. Completion is tracked centrally. Decisions trigger revocations through the same provisioning engine that granted access. Exportable artifacts for the audit cycle.
Review campaign overview — scope, status, remediation
Campaign dashboard: scope summary, status and outcome breakdown, and remediation needed.
Campaign lifecycle
A campaign, start to finish.
Scope.
Choose the population — users, resources, Grants — and the cadence. Plan before you launch: dry-run the policy against a grant, preview the reviewer load to estimate how assignments fall across reviewers, and simulate the remediation blast radius. The campaign owner gets a single dashboard of what’s in scope and where the campaign stands.
Reviewer assignment.
Reviewers receive a scoped queue — only the access they’re responsible for attesting to. When a primary reviewer can’t be resolved — a missing manager, an empty group, an inactive user — routing falls back to configured fallbacks, then to admins or owners, so work doesn’t stall in an empty inbox. And the access subject can’t review their own grant.
Decisions.
Reviewer acts on each item: keep or revoke. Revocations produce provisioning operations through the standard pipeline — the same per-step journal, retry semantics, and audit trail as any other change. When a revoke would be undone immediately — access that policy, a workflow, or a schedule would just re-grant — the remediation is held until an admin records how the source was addressed, so the evidence doesn’t read “revoked” for access that’s still live.
Close-out.
The owner sees a status and outcome breakdown — items decided, kept, revoked, and how many still need remediation. Export produces a campaign artifact: scope, per-item decisions with the reviewer on record, and the provisioning operations that followed.
Accountability by design
Why campaigns actually close.
Reviewers see only the access they are responsible for. Due-soon and overdue reminders fire automatically. When a reviewer doesn’t act, high-risk items escalate through the configured fallback chain or to admins. Revocations flow through the same provisioning engine that handled the original grant, with evidence recorded as removal proceeds.
Coverage without reassignment
When the reviewer is out.
A reviewer can name a delegate for a fixed window or as a standing arrangement. While that delegation is active, the review steps assigned to the reviewer also surface in the delegate’s queue, labeled for the reviewer they’re covering, and the delegate can decide them. Both are notified as work arrives and as reminders fire, so a campaign doesn’t sit waiting on someone’s return.
Nothing is reassigned. The reviewer keeps their full queue and the assignment on record is never rewritten, so responsibility stays clear. A delegated decision is recorded under the person who actually made it. Delegation runs a single hop: a delegate can’t pass the queue on again. It covers steps assigned to a named user, not group assignments, where any member can already act. Separation of duties also applies to delegates: the subject of a review can’t decide it.
Exportable evidence
Evidence that exports.
Every campaign produces an exportable artifact containing scope, per-item decisions with the reviewer on record, and the provisioning operations triggered. It’s generated server-side, one evidence packet per item, each record carrying its own content hash, so re-exports of the same decision are byte-identical and verifiable. The artifact lands alongside the rest of the audit evidence: the execution journal, the versioned state per assignment, the approval provenance. Auditors can use these records to see what changed and why.
Review campaign artifact — scope, decisions, revocations
Campaign export artifact: scope, per-item decisions, and the provisioning operations that followed.
Bring a real attestation cycle.
Sign up free. Bring a cadence you’ve struggled to complete and run it in Owlie.