Help centre

Compliance

Access recertification

Quarterly campaigns per portal: assign a reviewer, decide every item, sign off, and download the evidence CSV and audit reports.

Campaign list

ControlWhat it does
Open this quarter's campaigns nowButtonAdministrators only. Creates this quarter's campaign for every connected portal instead of waiting for the schedule.
Open campaignButtonOpens the review for that portal and quarter.
Download evidence CSVButtonAvailable once a campaign is signed off. Downloads every decision with reviewer, timestamp and reason.

Status badges read In progress while decisions are outstanding and Signed off once the reviewer has signed.

Reviewing a campaign

  1. 1Assign a reviewer from the drop-down. Only the named reviewer, or an administrator, can record decisions.
  2. 2For each person choose Keep access, Change access or Revoke access, adding a reason where useful.
  3. 3When every item has a decision, select Sign off. The sign-off is timestamped and immutable, and locks the campaign.
  4. 4Download the Evidence CSV, then generate the ISO 27001 and SOC 2 reports if you need narrative wording.
ControlWhat it does
Keep accessButtonConfirms the person's current access is still appropriate.
Change accessButtonFlags that access should be reduced. Follow up in Provisioning, Moves.
Revoke accessButtonFlags that access should be removed. Follow up in Provisioning, Offboard.
Sign offButtonReviewer only. Records the sign-off statement, totals and timestamp and locks the campaign.
Evidence CSVButtonDownloads the decision record for auditors.
GenerateButtonCreates the ISO 27001 policy or SOC 2 attestation wording from the campaign's aggregate results. Shows as Regenerate once a report exists.
Save changesButtonSaves your edits to the generated report.
Download .mdButtonDownloads the report as Markdown.