Luna recommendations in access reviews
What Luna does in an access review
Luna is Ploy's AI agent. In an access review, Luna analyses the accounts assigned to a reviewer and recommends an outcome for each one: approve the access, reject it, or flag it for a closer look. Every recommendation comes with the reasoning behind it, so you see why Luna reached its conclusion, not just the conclusion.
The point is to take the routine work off reviewers. Accounts where the signals clearly line up get a recommendation you can accept in one action, so your attention goes to the accounts that genuinely need human judgment.
Where recommendations appear
Reviewers see Luna's output in the Recommendations tab of their review, alongside the list of all entitlements. Each recommendation groups the accounts it covers and shows Luna's recommended outcome and the reasoning behind it, so you can judge the group before acting on it.
In the admin dashboard, the account-level review table has a Luna Discrepancies column showing what Luna's evidence analysis flagged for each account (see the last section below).
The three outcomes Luna recommends
Luna places each account into one of three buckets, and shows its reasoning for each:
Approve: the signals around the account consistently suggest the access is appropriate for the person who holds it.
Reject: the signals suggest the access is not appropriate and should be removed.
Needs review: Luna does not have enough confidence to make a clear call. These accounts have mixed signals or incomplete data, and they are the ones most worth your attention.
The reasoning is written for the reviewer: it states the specific signals that drove the recommendation, so you can check Luna's read against your own knowledge instead of trusting a label.
Accepting a recommendation
Accepting a recommendation applies it as your decision for the accounts it covers, and you can accept a whole recommendation group in one action. The decision is still yours either way: Luna assists with the review, it does not replace it. If you disagree with a recommendation, make your own decision on the account instead.
When your decision matches Luna's suggestion, Ploy records that the recommendation was accepted for that account as part of the review's audit trail, so admins can later see where reviewers agreed with Luna and where they overrode it.
For the full walkthrough of decisions, notes, and submitting, see the reviewer guide to completing a review.
When recommendations are generated
Recommendations are generated automatically as part of the review, per account set. There is nothing to switch on, and each reviewer gets recommendations for the accounts assigned to them. If an account set is reassigned to a different reviewer, recommendations are regenerated for the new reviewer's accounts.
Generation runs one review at a time. If Luna produces an unusable recommendation group, that group is dropped but every valid recommendation stays available, and the Recommendations tab keeps working rather than failing as a whole. There is no action to regenerate recommendations across a whole cycle; reassigning an account set is what triggers regeneration.
For where reviews come from in the first place, see how review cycles work.
Luna Discrepancies in the admin review table
The account-level review table in the admin dashboard includes a Luna Discrepancies column. It lists the mismatches Luna's evidence analysis found for that account, each with a tooltip containing Luna's reasoning:
Missing user: a user the analysis could not match to Ploy.
Incorrect Entitlement: an entitlement mismatch, shown with the entitlement names the evidence lists.
Not in evidence: a user the analysis could not find in the evidence.
Accounts with no discrepancies show a dash. A discrepancy is displayed struck through once it no longer applies, for example when the account has been reviewed or removed, or the entitlements now match the evidence.
Admins see reviewers' accepted and overridden recommendations when they approve a submission; see Approve an access review for the approval stage.