Set up an access review with indirect access
Indirect access (also called transitive access) is access held through groups, roles, or nested permissions rather than a direct assignment. Reviews include it only after you turn on Include indirect access in the review wizard: it is off by default, for both recurring campaigns and one-off reviews. The setup control is labeled Include indirect access; review rows use the badge Indirect.
You set it up in the same wizard you use for any review, under Access Reviews in the admin dashboard. See Article 3: Creating a Campaign for the full wizard walkthrough.
Turn on indirect access
Go to Access Reviews in the admin dashboard. Start a recurring campaign from the Campaigns view, or a one-off review from Simple reviews. Both open the same creation wizard.
Work through the wizard to the scope step, where the live preview panel shows the resources and accounts your filters match.
Turn on Include indirect access. It sits in the preview controls next to Group by person, and is shown once a valid preview has loaded. Its accessible name is Include access held through other resources.
Wait for the preview to refetch. It now includes accounts that hold the reviewed access through other resources, and each row is identified as Direct or Indirect.
Scope limits to know before you save
Two settings in the wizard do not combine with indirect access:
Entitlement only review type. Indirect access cannot be reviewed per entitlement yet; the setup fails with
Indirect access cannot be reviewed per entitlement yet. Switching to Entitlement only also resets the toggle to off.Five filters cannot match indirect access: Last accessed, Access level, Managed access, Managed access status, and Access tags. With any of them in the scope, the indirect part of the preview returns no matches.
An incompatible filter does not block setup. Ploy shows a warning and the scope returns direct rows only, for example: Last accessed cannot match indirect access, so this scope will return direct rows only. Remove it to review access held through groups. Remove the filter if you meant to review group-held access.
What reviewers see
In the review, the Access column shows Direct or Indirect for each account. An indirect row shows 1 route or a route count, with a Show access chain control that opens the full path as a chain of resources from root to leaf, hop by hop. A row with no stored path shows No routes recorded. Access chains are traced up to 10 hops deep.
What happens when indirect access is denied
Denying an indirect row does not deprovision the account from the reviewed resource. Ploy creates a manual task instead, titled Remove [person] from the groups granting [resource], sent as an Indirect access removal request to the assignee. Completing the task removes the person's membership on the granting path while leaving the intermediary-to-resource link intact. Refusing it leaves the access in place and creates a retryable issue titled Indirect access removal failed.
You also cannot remove an individual entitlement from an indirect row, because the access is held through a group. Deny the whole row instead, and Ploy will raise the group-removal task. See Article 7: Completing a Review — Reviewer Guide for the reviewer workflow, and Article 10: Outcomes & Automated Remediation for how outcomes work.
Which integrations surface indirect access
Transitive detection depends on the integration producing resource-to-resource edges in the access graph, for example group-to-group or group-to-app memberships. Confirmed sources include Okta groups, Google Workspace groups and roles, Microsoft Entra ID groups, roles, and conditional access policies, GitHub enterprise-to-organization links, AWS permission sets and policies, and others. If an integration has no such edges, its resources show direct access only. To inspect the paths on a single resource, see View transitive access for resources.