Types of access review
Ploy runs three types of access review: Review each user in Ploy (the default), Attestation only, and Entitlement only. You pick the type in the Review type field when you set up a review. The type decides what one review row represents, who acts on it, and what a rejection removes.
Where you pick the review type
The Review type field is required and sits next to the Campaign type field: in the Campaign Basics step of the campaign wizard, or the Review setup step of a simple review. Both wizards open from the Access Reviews page, campaigns from the Campaigns view and one-off reviews from the Simple reviews view.
The campaign wizard continues through Campaign Basics, Review Scope, Cycle Templates, and Review process. The simple review wizard runs Review setup, Cycle Templates, and Review process. See Create an access review campaign for the full walkthrough, and Campaigns vs. one-off reviews for choosing between the two modes.
Review each user in Ploy
The default type. Ploy lists everyone with access to each system. Reviewers decide on each person, and any removals are actioned through Ploy.
Use it whenever you want a recorded, per-person decision for systems Ploy can see into. Each account appears as a row a reviewer decides on, and a rejection removes the person's access through Ploy. How reviewers work through those rows is covered in Complete a review: reviewer guide.
Attestation only
No user-by-user review happens in Ploy. The owner of each system attests that they've reviewed access in the system itself and actioned any changes. Use this for systems Ploy can't see into.
When you select Attestation only, Ploy clears the review stages in the wizard and the reviewers assigned in the review's scope become the attestors. Who you can assign is covered in Defining scope in an access review.
Entitlement only
Each role a person holds is reviewed on its own. Reviewers decide per role, and a rejection removes only that role, never the whole account. Use this for systems where one account carries several roles.
Entitlement only cannot be combined with indirect access. Setting up a review with both fails, and switching to Entitlement only resets the Include indirect access toggle to off. See Set up an access review with indirect access.
What you see on each review row
Admins track a review at two levels in the dashboard: one row per resource in the review table, and one row per account in the accounts list. Reviewers see the same access in the employee portal as one row per person. The columns below are listed in the order they appear.
Table | Columns |
|---|---|
Review table (one row per resource) | Resource, Due, Stage, Completion, Status, Accounts, Revocations, Reviewers, Attestation, Started, Completed, Evidence, Hash, plus Compliance when a compliance connection exists |
Accounts list (one row per account) | Account, Decision, Identity, Access, Entitlements, Data Source, Luna Discrepancies, Reviewers, Status, Reviewed At, Reviewed By, Notes, Remediation Type, Remediation Status, Remediation Action, Remediation Completed At, Actions |
Resource rows
A resource row carries one of three statuses: In progress, Ready for approval, or Complete.
The Attestation column offers the actions Approve, Approve sets, and Attest & Approve.
The Evidence column tracks the review certificate and its delivery to a compliance connection. It shows Certificate or Generating while the certificate is prepared, Push or Retry to deliver it, and the connection's name with Sent to, Sending to, or Failed once delivery is under way. Push appears only when a certificate exists and a compliance connection can receive it; Retry appears when a delivery failed.
Account rows
The Decision column shows a pill for each account's current state: Pending, Required, No Response, Not Required, Out Of Scope, Compliant, Non Compliant, Appropriate, Not Appropriate, or Adjust Entitlements.
The Status column shows one of: Requires review, Flagged for change, Complete, Already removed, Removed, Excluded, or Removed, not in source.
Remediation statuses appear in their own columns: Pending, Outstanding, Complete, Failed, or Cancelled.
Each row can offer two actions: Reassign this account and Re-sync from current data. They appear only where the row is eligible, so some rows show no action buttons. Above the list, set controls apply to the selected accounts: Approve, Request Revision, Approve All, Request Revision All, Reassign, Remove from Scope, and Re-sync.
In a multi-stage review, the Removed tab adds a Stage column at the front.
Reviewer rows
In the employee portal, a reviewer sees one row per person who holds the access being reviewed, with the person's name on the row. Each row offers:
View account details, which opens the account's identity, access, peer comparison, role, and activity
Raise a query, after which the row shows Queried until a response arrives, then Response received
One decision action for each outcome the admin configured for the campaign
Depending on the account, a row can also offer Remove this entitlement, Revoke all, or Choose identities. Reviewers who spot wrong data can fix it from the row: Fix incorrect data, Edit an account's entitlements, Add a user Ploy is missing, Remove a user who doesn't exist, or View fixes. Entitlement corrections are available only for accounts in sets assigned to that reviewer, and group-held entitlements are listed together and must be removed together.
On desktop, the table header and the Account column stay frozen while you scroll, and the list opens sorted A-Z by account name.