Skip to main content

Conducting an access review

Roles and permissions

The following roles can conduct an access review:

  • Administrators who have been assigned as the Reviewer or Sysadmin for user records in the access review

  • Compliance managers who have been assigned as the Reviewer or Sysadmin for user records in the access review

  • Users who have been assigned as the Reviewer or Sysadmin for user records in the access review

Access reviews are conducted by a reviewer and a sysadmin. The reviewer checks user access for each user in an application user list and indicates in Hyperproof whether or not that user's access needs to be updated. The sysadmin first modifies the user's access in the application itself, then attests in Hyperproof that the update has been made. Reviews and updates can be done by any number of people in your organization and are not limited to the default reviewer and sysadmin configured when the application user list is created.

To begin the review process, make sure the following tasks are complete:

  • An employee directory has been imported on the Setup tab of the access review. This is optional, but recommended. The directory contains information about each user's job title and department, which may be helpful in determining the appropriate access to the application being reviewed.

  • One or more application user lists have been imported on the Setup tab of the access review. This is required. The application user lists create a grid with a row for each user record where reviewers and sysadmins can record their work.

  • The controls that will be satisfied by the access review have been linked to the access review. When you generate proof at the end of the review, it is attached to the access review. You can manually attach it to the linked controls.

  • The status of the access review has been changed from In setup to In progress. You have two options for changing the status:

    • Open the access review Details tab and set the Status field to In progress.

    • Open the access review Review tab and click the Launch review button.

    The status next to the access review title now displays the percentage of the review that is complete.

When all of the setup tasks are complete, conduct your review as follows: