Access Reviews
Enterprise Feature
Access Reviews are available exclusively in OpenGRC Enterprise, currently in Beta. Learn more about Enterprise.
Access Reviews (User Access Reviews, or UAR) let organizations periodically verify who has access to which applications, and produce the audit evidence to prove it. A campaign creates recurring or one-off review rounds; each round walks every application in scope through a three-step process and finishes with a manager sign-off that becomes the audit record.
Overview
Access Reviews help organizations:
- Run recurring or one-off access review campaigns across applications
- Walk each application through a structured three-step process: package, verification, manager decision
- Notify each participant automatically with customizable email templates
- Snapshot owners, instructions, and reference files at launch so a closed round's evidence never shifts
- Track open, overdue, and completed items from a single dashboard
- See which applications haven't been reviewed recently
How It Works
The Three-Step Review Process
Each review item (one per application, per round) moves through up to three steps:
| Step | Role | Responsibility |
|---|---|---|
| 1. Review Package (optional) | System Owner -- the technical administrator who can export the application's user list | Exports the current user list and describes how it was produced. Applications without an evidence requirement skip straight to verification |
| 2. Verification | Application Owner -- the business owner accountable for who should have access | Checks the list and attests that access is correct, or spells out the changes required |
| 3. Manager Decision | UAR Manager -- the person running the campaign | Approves and closes the item, parks it while changes are worked out, or restarts the review |
When every item in a round is decided, the UAR Manager finalizes the round with their sign-off -- that record is the audit evidence.
Creating a Campaign
- Navigate to Access Reviews and click New Campaign
- Under Campaign, set the Name, UAR Manager, optional Description, Status (Active or Paused), and Due within (days) -- how long reviewers get after a round launches
- Under Schedule, choose a Frequency (None, Monthly, Quarterly, Semi-Annual, or Annual) and optionally a Next run date to launch automatically; leave it empty to launch rounds manually
- Under Review Package, choose whether the System Owner prepares the package first (the full three-step flow) or to go straight to the Application Owner (when the verifier already has the access data), set Default instructions to the System Owner, and choose whether Verifier evidence is Optional or Always required
- Under Reference Materials, upload files reviewers keep asking for (an employee roster, a recent leavers list, a role matrix) and choose which step sees each one. Files are snapshotted per round, so a later replacement only affects future rounds
- Under Scope, either leave Review all active applications on, or turn it off and pick specific applications or assets flagged for access review
- Review the What This Campaign Will Do summary -- it shows how many review items the next round will create, when reviewers will see it's due, and (if a frequency is set) the schedule of upcoming rounds -- then click Create
Launching a Round
Clicking Launch UAR opens a Launch [date] Round screen before anything is sent, so you can review and adjust the round first:
- Three status chips summarize the round: Ready to launch (applications with both owners resolved), Package step skipped (applications with no System Owner set, so the Review Package step is skipped for that item), and External reviewers (owners who are portal users, which will get a magic link by email instead of an in-app notification)
- A Review targets in scope table lists each application with its System Owner and Owner (verifier) -- adjust either assignment here, or add another reviewer with +. A per-application Package step toggle lets you override the campaign's default for that one application
- An Email participants toggle controls whether each assignee is emailed their step request. When off, internal users still see their work on the To-Do page
Click Launch N Review Items to start the round.
Portal Users as reviewers
A System Owner or Application Owner can be a Portal User rather than a full internal OpenGRC user. Portal User reviewers complete their step via a magic link emailed to them, the same pattern used elsewhere for external reviewers (e.g. vendor surveys).
Running a Round
Once launched, the campaign page shows:
- A round selector for viewing past rounds
- Stage counts across the round: Package, Attestation, Manager, Closed
- A table of review items with Review Target, Type, a progress stepper, who the item is Waiting On, Status, Resolution, and Due date
Each review item has its own detail page showing a full Item History timeline (round launched, package submitted, attestation recorded, decision made), the Review Package details (source system, data-as-of date, how the list was produced, System Owner, and any attached files), and the verifier's Attestation once submitted.
Item Statuses
| Status | Meaning |
|---|---|
| Awaiting Review Package | Waiting on the System Owner to assemble the package |
| Awaiting Validation | Waiting on the Application Owner to verify access |
| Awaiting Manager Review | Waiting on the UAR Manager's decision |
| Waiting on Changes | Parked while reported changes are worked |
| Closed | Decided -- Resolution shows the outcome (e.g. Approved) |
Finalizing a Round
Once every item in a round is decided, click Finalize Round to record the UAR Manager's sign-off -- this is the record you present as audit evidence. Use Export Round to download the round's evidence package.
Email Templates
Click Email templates from the Access Reviews page or a campaign to customize the three notification emails, one per step:
| Template | Sent to |
|---|---|
| Evidence Request | System Owner, at the Review Package step |
| Validation Request | Application Owner, at the Verification step |
| Manager Review | UAR Manager, at the Manager Decision step |
Each template has a Subject, optional Preheader, and a Markdown Body built from placeholders such as {{recipient_name}}, {{application_name}}, {{campaign_name}}, {{due_date}}, {{review_procedure}}, {{organization_name}}, and the required {{action_url}} -- the link recipients use to complete their step. Use Preview or Send test to me before saving, or Reset to default to revert.
Dashboard
The Access Reviews home page shows:
- Open Items, Overdue, Waiting On You, and Closed This Round counts
- Where the Current Round Stands -- a breakdown of items by stage (Package, Attestation, Manager Review, Closed) with percent closed
- A list of access review campaigns with each one's latest round progress
- Needs Your Attention -- items that are overdue or blocked
- Review Coverage -- how many applications have been reviewed at least once in the last 12 months, surfacing applications with no recent review
Best Practices
- Set a recurring Frequency for applications that need regular review cadences instead of launching rounds manually
- Skip the Review Package step for low-risk applications where the verifier already has the access data, to speed up the round
- Require verifier evidence for high-risk or regulated applications, and keep it optional elsewhere
- Keep reference materials current -- an outdated leavers list undermines the verifier's ability to attest accurately
- Finalize every round promptly once all items are decided -- the sign-off is what makes the round usable as audit evidence
- Watch Review Coverage to catch applications that haven't been reviewed in the last year and add them to a campaign
Permissions
- Creating and managing campaigns requires access to the Access Reviews app
- System Owners and Application Owners complete their step via the secure link in their notification email
- Only the UAR Manager assigned to a campaign can make Manager Decisions and finalize a round