Remove when unused
Remove when unused is continuous cleanup. It watches one app or permission and takes the access back once it has gone a set number of days without being used. Use it to stop access quietly accumulating on people who no longer need it.
What it does
The effect's own words: "Ploy removes this access once it has gone a set number of days without being used."
The policy sentence states the bound plainly, for example: Access to Google unused for 5 days is removed. A second live example from the same org reads: Access to Jira Service Management unused for 30 days is removed.
This only applies to access rows where Ploy has recorded usage. If we have no recorded usage for an access row, this policy will not revoke access to the row.
Like the other cleanup effects, it holds no access of its own. It cannot give anybody anything, it can only take back what is already there.
Write one
Open Managed Access, go to the Policies tab and choose New policy.
Under Who, choose whose access is in scope. Leave it empty and the sentence possessor becomes "Anyone's".
Under What, pick the Remove when unused effect card.
Name the target. It has to be one specific app or entitlement, so Everything is not offered.
Set the threshold in the days field. It starts at
60. The line underneath tells you what you just wrote, for example "Removes access unused for 60 days automatically."Under Revocation enforcement, choose Suggest removal or Remove automatically.
Check the preview column, then choose Create & activate.
Leave the threshold blank and saving is refused with "Set the number of days without use before this policy acts". Type anything that is not a whole number above zero and you get "Days without use must be a positive whole number".
Who applies the removal
That is the only thing the enforcement setting decides on this effect.
Setting | What happens when access goes stale |
|---|---|
Suggest removal | The removal is proposed and waits. A person approves each one. |
Remove automatically | Ploy takes the access back without waiting for anybody. |
Suggested removals land in the same queue as every other suggested removal: the panel on the Managed Access overview, the full list under the Access tab, and a Suggested removals tab on the policy itself, with a tick to remove and a cross to keep. Access the policy has already taken back is listed on its Removed tab, which is history only and has no buttons.
Good to know
There is no suspend option. Auto-suspend is refused on this effect: "A policy that removes unused access cannot suspend it instead."
There is no manual override setting either. Reverse, Flag and Log are not offered here.
Flagging is now the suggest setting. Flagging unused access used to be its own effect. It is not any more: write a Remove when unused policy and set it to suggest, so a person approves each removal.
It never counts as an access-holding policy. On the Enforcement card these policies are counted separately, as in the chip "1 low usage policy", because the enforcement mix describes policies that hold access and this one does not.
Identity requirements are not available. The "via identities where" panel is refused on this effect today: "Account requirements are not supported on guardrail policies yet."
Short thresholds are allowed. Nothing stops you writing 5 days, and one of the live examples above does. Preview it first: on a heavily used app a short threshold will pick up people who are simply on leave.