Create an access review campaign
You create access reviews from the Access Reviews page in the admin dashboard. Click Create campaign to build a recurring or reusable campaign, or Create review to run a simple one-off review of a single app. Both open the same wizard; simple reviews use a shortened version. For help choosing between the two, see Campaigns vs. one-off reviews.
Before you start
You need admin access to the Ploy dashboard, and a clear answer to three questions:
What access are you reviewing? Which apps, which employees, which access attributes.
Who will review it? Managers, resource owners, or a specific team, plus a fallback if they are unavailable.
What can reviewers decide? The outcome options you want to offer them.
Start the wizard
Open Access Reviews in the admin dashboard.
On the Campaigns view, click Create campaign. For a simple one-off review, switch to the simple reviews view and click Create review.
The campaign wizard has four sections, in order: Campaign Basics, Review Scope, Cycle Templates, and Review process. The simple review wizard has three: Review setup, Cycle Templates, and Review process. There is no separate create URL; both wizards open from the Access Reviews page.
Campaign Basics
This section sets the campaign's identity, type, schedule, and tags. Simple reviews skip this section and use Review setup instead (see below).
Enter the campaign name. It is required; pick something that will still make sense in six months, for example "Quarterly admin access, cloud infrastructure" rather than "Q1 review".
Add a short description. Optional, but useful context for other admins and auditors reading the record.
Choose the Campaign type: Recurring Campaign automatically creates review cycles on a regular schedule, while Ad-Hoc Campaign creates a campaign template you use to manually run new cycles as needed, with no automatic scheduling.
Set the Review type, which sits beside Campaign type. It is required and defaults to Review each user in Ploy. The other options are Attestation only, for systems Ploy cannot see into, and Entitlement only, for systems where one account carries several roles.
For a recurring campaign, choose the cycle frequency: Weekly, Monthly, Quarterly, Biannually, or Annually. Ad-hoc campaigns have no frequency.
Set the start date. It is required for recurring campaigns and optional for ad-hoc campaigns.
Set the Review period: how long reviewers have from the start of a cycle before reviews are due. Options are 1 Week, 2 Weeks, 1 Month, 3 Months, 1 Year, or a custom number of days.
Add tags in the Tags field, for example PCI, SOC, or ISO. A campaign can have up to 20 tags of up to 50 characters each. Tag matching is case-insensitive, and existing tag names are suggested as you type.
Review setup (simple reviews)
The simple review wizard merges the campaign's first two sections into Review setup. The campaign name and description fields are not shown; the review name is derived from the app you pick.
Choose the resource under Resource (what to review).
Optionally narrow the scope under Filter (optional, narrow by employee or access). This appears after you select an application.
Set the schedule with the same controls the campaign wizard uses: start date, review period, review type, and tags.
Choose who reviews under the Assign Reviewers (who is reviewing) field, including the option to allow reviewers to review their own access. Simple reviews do not support per-resource reviewer overrides.
Review Scope
This section defines which access the campaign reviews, and who reviews it.
Scope is built from resource, employee, and access filters. Rather than repeating every filter here, see Defining scope in an access review and Configure review scope and filters for the full filter breakdown and how they combine.
The same section holds the reviewer assignment. Under Assign Reviewers (who is reviewing), pick a saved configuration from the Select assignment dropdown, or click Create New to build one inline (the button becomes Edit once a configuration is selected). You can also click Add overrides under Overrides (optional) to route specific resources to different reviewers. How the strategies work is covered in Assign reviewers.
Cycle Templates
Here you define the title and description each generated cycle will carry.
Enter the Campaign Cycle Title Template. It is required.
Enter the Campaign Cycle Description Template. Optional.
Insert variables by clicking their labels under Available variables:
Month,Quarter,Year, andCampaign Name. Ploy fills the date variables from the date the cycle is generated. The same four variables are available in both fields.Check the live Preview beside the editors to see the generated cycle title and description before saving.
Review process
This section decides what reviewers can choose and what Ploy does with each decision. It is identical for campaigns and simple reviews.
Outcome sets
You pick one of three predefined outcome sets. Each gives reviewers four choices:
Outcome set | Reviewer outcomes |
|---|---|
Access Validation | Required, Not Required, Needs Adjustment, Out of Scope |
Compliance Review | Compliant, Non-Compliant, Needs Adjustment, Out of Scope |
Entitlement Review | Appropriate, Not Appropriate, Needs Adjustment, Out of Scope |
The removal outcome (Not Required, Non-Compliant, or Not Appropriate, depending on the set) can trigger deprovisioning, and Needs Adjustment starts entitlement remediation: Ploy uses the resource's Adjustment Flow if it has one, otherwise it creates a manual task for the relevant team.
Two independent action settings control deprovisioning in Action settings:
Deprovision access automatically when "Not Required" is selected: runs deprovisioning when a reviewer chooses the removal outcome. The outcome name in this label follows the outcome set you selected.
Allow auto-deprovisioning on account set approval: lets the approving admin choose deprovisioning at approval time instead.
You can enable either, both, or neither.
Other review process settings
Record decisions only — records the reviewer's decision but takes no automatic action.
Enable notifications — notifies reviewers when reviews are assigned.
Multi-stage review — sends approved access matching a filter to a second reviewer.
Attestation — configures who signs off the completed review and which statements they certify.
Escalation — configures reminders, reassignment, notifications, and deadline-extension behavior.
How outcomes map to remediation after the review is approved is covered in Review outcomes and remediation.
Save the campaign
The finish button reflects your schedule:
An ad-hoc campaign with no start date creates the campaign template only.
A start date of today creates the campaign and starts the first cycle immediately.
A later start date creates the campaign and schedules the first cycle for that date.
After you save, a "Campaign Created" confirmation appears and you land on the campaign detail page. The campaign is listed in the Campaigns view, which groups campaigns into Campaigns with active cycles and All campaigns.
After creation
Recurring campaigns generate each cycle automatically on the scheduled start date; if you chose a start date of today, the first cycle started during creation. You can start a cycle at any time with Start New Cycle, available from a campaign card's menu and from the campaign detail page, then confirm with Start Cycle. Generation runs in the background and can take a few minutes for large campaigns.
What happens inside a cycle once it starts is covered in How review cycles work.