Complete a review: reviewer guide
This guide is for reviewers: the people assigned accounts to certify in an access review. You open the review from your notification link, work through one row per person with access, decide on each account, and submit when every decision is made. How reviews are set up and approved from the admin side is covered in How review cycles work and Approve an access review.
Open your review
When you're assigned a review, Ploy notifies you by email or Slack (depending on your organisation's notification settings) with a link to the review in the Ploy employee portal. The portal is a separate app from the admin dashboard, at your organisation's own portal address. If you have no active session, the link logs you in with a magic link, so no password is needed.
Your review counts as Not started until you open it, then In progress.
What each row shows
The reviewer list shows one row per person with access. Rows show the account or person's name, and every action opens from the row. On desktop, the table header and the Account column stay frozen while you scroll, and the list opens sorted A to Z by account name; the Account header reverses the order.
View account details
Each row offers View account details, which opens the full record for that person's access:
Identity — provider, username, external ID and status
Access and Peer comparison
Role — job title and department
Activity — Last used, Access granted and Access expires, or Never
Make a decision
Each row carries one decision action for every outcome your admin configured for the campaign. The labels you may see include Required, Not Required, Needs Adjustment, Out of Scope, Compliant, Non-Compliant, Appropriate, Not Appropriate and Removed; what each outcome does is covered in Review outcomes and remediation.
Find the person's row and choose the decision action for your outcome.
The confirmation states the consequence, for example "Their access will be kept.", "Their access will be removed." or "No access is removed by this decision." Add a note if you want one (optional), then Confirm, or Confirm and certify removal where the access is being removed.
Once the decision is recorded, the row shows Decision saved.
Depending on the account, the row can also offer Remove this entitlement, to remove a single entitlement, Revoke all, to remove every entitlement on the account, and Choose identities. Luna can also recommend decisions for the accounts in your review; see Luna recommendations in access reviews.
Raise a query
If you can't judge an account yet, Raise a query from the row sends your question to the admins. The row shows Queried while you wait (or "Sent to the IAM team. Awaiting their response."), then Response received once they answer.
Correct the data in a review
Where the review's data is wrong, the row offers these fixes:
Fix incorrect data
Edit an account's entitlements
Add a user Ploy is missing
Remove a user who doesn't exist
View fixes shows the corrections already made. You can correct entitlements only for accounts in sets assigned to you.
Access held through a group
Entitlements a person holds through a group are listed together and must be removed together. Adjusting access that comes through a group routes through the resource's configured adjustment flow rather than a direct edit on the account.
Statuses you may see
Beyond your own decisions, a row can show:
Already Removed — the decision records access that was removed before the review
Sent to the IAM team. Awaiting their response.
De-provisioning started: this can't be changed
Attach evidence
If you have documentation that supports your decisions, such as approval emails or usage reports, you can attach it to the review as evidence. How evidence is stored and used is covered in Review evidence and compliance certificates.
Submit your review
Submit your decisions before the due date shown on the review; if it passes, your admin can send you a reminder. When your final action completes the review, the submit confirmation opens automatically, and it appears at most once per review. Submitting locks your decisions: you can't change them unless an admin sends the review back.
If your review is sent back
An admin can send your account set back with a revision message when a decision needs a second look. You receive a notification with their message, the set reopens in your portal, and you update your decisions and resubmit.
What happens after you submit
Nothing is actioned until an admin approves your submitted set. Once it's approved, the removals and entitlement adjustments from your decisions are carried out and recorded as part of the audit trail; see Approve an access review.