Configure review scope and filters
You set what an access review covers in the Review Scope section of the campaign wizard. Add filters to choose the resources, employees, and access in scope, then check the live preview before you save. Simple reviews use the same structure in their Review setup step.
Open the scope step
Go to Access Reviews in the admin dashboard. Start a recurring campaign from Campaigns, or a one-off review from Simple reviews. Both open the same creation wizard. For the full wizard walkthrough, see Create an access review campaign.
Work through the wizard to the Review Scope section. In a simple review, the same filters sit in the Review setup step, where the resource to review is set in the Resource (what to review) field.
Add a filter
Every filter has three parts: the field to match, an operator, and a value. In Review Scope, click Add filter (what to review) and set the three parts. For example, Managed app with operator Equals and value Enabled includes only applications managed by Ploy that are currently enabled; Disabled matches discovered, unmanaged applications.
Filters fall into three categories:
Resource filters choose which apps and resources are reviewed: Resource, Resource Type, Integration, Tags, and Managed app.
Employee filters choose whose access is reviewed: Department, Status, Job Title, Country, Hire Date, and Profile.
Access filters choose which access is reviewed: Identity Type, Is Non-Human Identity, Entitlements, Access Length, Last Accessed Date, Access Level/Role, Managed Access, Provisioning Status, and access Tags.
How filters combine
An account is in scope only when every condition matches. Conditions are combined with AND within each category and across categories.
Multiple values inside one condition are combined with OR. For example, Department is one of Engineering, Finance AND Country is US AND Identity Type is Human includes accounts for people in Engineering or Finance in the US with human identities, and nothing else.
Check the live preview
The preview panel next to the filters shows the campaign your current settings would generate, so review it before saving.
One row per matching resource, with Resource, Accounts, Status, and Reviewers columns. The Accounts count is the total number of matching accounts for that resource, not just the sample rows shown.
Expand a resource to load sample account rows with User, Access, Identity, Entitlements, and Reviewers.
Group by person, on by default, merges the identities belonging to the same person on the same resource into one row. Turn it off to see one row per identity.
The search and filter controls inside the preview narrow only what is displayed. They do not change the campaign's scope.
Five filters cannot match indirect access: Last accessed, Access level, Managed access, Managed access status, and Access tags. With any of them in the scope, the indirect part of the preview returns no rows. See Set up an access review with indirect access.
Review entitlements only
Selecting the Entitlement only review type changes the grain of the review: one review row per matching entitlement instead of one per account, for per-role review and role-only removal.
With Entitlement only selected, add an Entitlements or Entitlement Type filter to choose which entitlement grants become review rows:
Equals includes only the named entitlements or types.
Not Equals excludes the named entitlements or types and keeps the account's other entitlements. An entitlement with no type remains when a type is excluded.
Entitlement-only reviews are never grouped by person, even with Group by person on, because each entitlement stays a separate review decision. The Include indirect access toggle is hidden for entitlement-only reviews.
How scope changes between cycles
When a recurring campaign generates a new cycle, Ploy re-evaluates the saved filters against your data at that moment. New joiners, new applications, and newly granted access that match the filters are included; access that no longer matches is not.
Each generated cycle is a snapshot. Data changes after a cycle starts do not rewrite its rows; use Re-sync from current data on a row to refresh it.
Related pages
Scope also controls who reviews the access and how denied access is removed: see Defining scope in an access review. To compare campaign and one-off review types, see Types of access review.