Access review reporting and compliance
Once a review cycle completes, three things cover your reporting and evidence: the Access Review Performance report tracks your review program, CSV exports give you the raw decisions, and compliance certificates prove the outcome to auditors, either downloaded as PDFs or pushed straight into Vanta, Hyperproof, or Oneleet. The audit trail underneath records every action taken along the way.
Track your review program with the Access Review Performance report
The Access Review Performance report is a ready-made system report, so there is nothing to build or configure: it summarizes scheduled, completed, in-progress, and overdue review cycles, how long reviews take to complete, and the removals and escalations that came out of them.
Open Reports in the admin dashboard.
Select the Access Review Performance report card.
The report is organized into four sections: Review cycles, Overdue cycles, Completion, and Individual reviews.
Exporting review data
An export contains one row per reviewed account, with the decision, the person and their access as they were at review time, and who reviewed them. Use exports to feed your own compliance tools or to hand auditors raw data alongside your certificates.
To export a single review, open the review and click Export to CSV in the review's detail sidebar.
To export several reviews at once, open the campaign detail page, select the reviews in the Reviews table, and click Export Selected.
Export Selected stays disabled until you select at least one review.
What the export contains
Category | Columns |
|---|---|
Decision | Resource Name, Resource Type, Outcome, Notes, Out of Scope Reason, Removed From Scope Reason, Removed From Scope At, Removed From Scope By |
Remediation | Remediation Type, Remediation Status, Remediation Due By, Remediation Completed At |
Person | Member Name, Member Email, Department (at review time), Job Title (at review time), Location Region (at review time), Location Country (at review time) |
Access | Identity, Role/Access Level, Entitlement, Entitlement Type, Access Kind, Access Path, Access Granted (at review time), Access Expires (at review time), Last Accessed (at review time), MFA Enabled (at review time) |
Data provenance | Data Source, Data As Of |
Reviewer and escalation | Reviewed By, Reviewed By Email, Reviewed At, Escalated, Escalated From, Escalated At, Completed By Escalated Reviewer |
Access Path traces indirect access as a readable chain, for example a team or role that grants the access; direct access leaves the column empty. Entitlement columns are filled for entitlement-scoped rows and left empty for whole-account rows.
Download and push compliance certificates
Every completed review has a compliance certificate PDF. For what a certificate contains, see Review evidence and compliance certificates.
In the review table, use the Certificate action in the Evidence column.
The column shows Generating while the PDF builds.
Push certificates to a compliance platform
Connect Vanta, Hyperproof, or Oneleet under Integrations > Compliance before pushing. The Push action appears in the Evidence column only when the review is complete, its certificate has been generated, and you have a compliance connection that can receive pushes. When a compliance connection exists, the review table also gains a Compliance column.
In the review table, click Push in the Evidence column.
Choose the document or control to send the certificate to.
You can also send every completed review in a campaign cycle in one batch. Ploy records the delivery status in the Evidence column, shown with the connection's name: sent, sending, or failed. When a send fails and the connection supports retries, Retry appears so you can send the certificate again.
Group campaigns with tags
Tags group campaigns by framework, such as PCI, SOC, or ISO. The Campaigns list filters by tag, and you can download certificates for every certified, non-archived review that matches the tags you select.
Open the campaign create or edit wizard.
In the Campaign Basics step, add tags in the Tags field.
A campaign can carry up to 20 tags of up to 50 characters each. Tags are trimmed and de-duplicated, and matched case-insensitively, so PCI and pci count as the same tag.
The audit trail
Every significant action in an access review cycle is automatically recorded in the audit trail: a chronological, immutable log of what happened, who did it, and when.
What the audit trail captures
Campaign and cycle events:
Cycle created (including the filters and settings used)
Review started
Campaign completed or archived
Reviewer actions:
Account set submitted (with reviewer identity and timestamp)
Revision requested (with the admin's message)
Account set approved (with approver identity)
Account-level decisions:
Each account reviewed: outcome, reviewer, and timestamp recorded
Outcome changed (if a revision was requested and resubmitted)
Account marked as already removed
Remediation events:
Remediation initiated (type, target account, who triggered it)
Remediation completed (outcome, timestamp)
Remediation failed (error details preserved)
Point-in-time snapshots
The audit trail preserves a snapshot of every account reviewed, captured when the review cycle was generated rather than when it was approved. This keeps the record historically accurate even if the employee's situation changed during the review. Snapshots include:
Department, job title, and manager
Location (region and country)
MFA status
When access was originally granted and when it expires
Last active date in the application
Viewing review history
All past cycles are preserved in the admin dashboard under the campaign they belong to. For any previous cycle you can see the full list of reviews and their outcomes, each review's progress, the decisions made on each account, remediation status and history, and the generated compliance certificates.
There is no time limit on how long review history is retained: completed cycles and their records persist in line with the Terms of Service and DPA you agreed to when signing up to Ploy.
What admins use reporting for
Goal | Where it lives |
|---|---|
Building an audit evidence set | Compliance certificates (downloaded or pushed to your compliance platform) alongside a CSV export of the decisions |
Tracking remediation | The remediation columns in the CSV export, and the removals and escalations in the Access Review Performance report |
Checking program health | The Access Review Performance report: completion rates and overdue cycles across campaigns |