Administrator guide
Access reviews
Define and schedule access review campaigns, follow them to the end, and produce the evidence pack.
An access review asks a manager or an owner to confirm that people still need the access they hold. Warde runs reviews as campaigns on your instance. Reviewers decide on the Reviews tab of My Access in your portal, removals go back through the same path as any other removal, and a campaign closes only when every removal is confirmed.
Campaigns are defined and run in ServiceNow. Warde does not import campaigns from SailPoint or another tool.
Before your first campaign
- Set where reviews open, reminders, escalation and evidence retention in Guided Setup step 11.
- Make sure reviewers hold the requester role. Reviewers are managers and owners from across the business, so if you grant the requester role to named groups, put them in one.
- Check that the Warde campaign scheduler scheduled job is active.
Define a campaign
Open Access reviews > Campaign definitions in the Admin Workspace and create one.
| Field | What to enter |
|---|---|
| Name | Each campaign launched from it is named after it, with the launch date |
| Description | Shown to reviewers under the campaign name. Say why the campaign is running and what to weigh. |
| Subject | Entitlement assignments to review single pieces of access, or Access bundle holdings to review whole bundles |
| Scope condition | Which access to review: a collection, an entitlement, a group of people, a risk level. Empty reviews all active access. |
| Bundle scope condition | For bundle holdings: which bundles. Only holders behind the current version reviews only people left on an older version by a change. |
| Reviewer strategy | Line manager of the access holder, Entitlement owner, Entitlement collection owner, or Access bundle owner |
| Fallback reviewer | Required. Reviews every line nobody else can. |
| Due in (days) | How long reviewers have, counted from launch. The default is 14. |
| Justification on revoke | Reviewers must give a reason when they remove access |
| Justification on bulk approve | Reviewers must give a reason when they keep several lines in one action |
| Active | Inactive definitions neither launch on schedule nor by hand |
If the reviewer strategy finds nobody, or would ask someone to review their own access, the line goes to the holder's manager, then to the fallback reviewer.
Access your identity system grants by its own rules, and access marked as automated in the identity system, is left out of reviews: the rule decides who holds it, not a reviewer.
Schedule it
| Run | Meaning |
|---|---|
| On demand | Launches only when an administrator selects Launch campaign |
| Once | Launches once, on the start date |
| Daily, Weekly, Monthly, Annually | Recurring. Weekly uses Day of week; Monthly and Annually use Day of month, and Annually uses Month. |
Starting is the date occurrences are counted from; a recurring schedule with no start date never runs. Ending is optional. Repeat every runs every Nth occurrence: Monthly with 3 is quarterly, Weekly with 2 is fortnightly.
Scheduled campaigns start when the Warde campaign scheduler job runs, daily at 06:30 instance time. That run time is the launch time for every campaign on the instance. A definition has one live campaign at a time: a launch, by hand or on schedule, is refused while the last one is still running, because two runs would give the same access to two reviewers.
While a campaign runs
When a campaign launches, Warde freezes its scope, reviewers and rules, creates one review task per reviewer, and emails each reviewer Access review assigned to you. The email links to the review on My Access.
| When | What happens |
|---|---|
| Before the due date | Reviewers are reminded the number of days before set in Guided Setup (default 3) |
| After the due date | The review is escalated to the reviewer's manager after the days set in Guided Setup (default 3). The manager can complete it. |
| A reviewer hands it on | Reassign review moves the whole review to someone better placed, and the hand-over is recorded |
| A reviewer is on leave | Platform delegates of the reviewer can work it, and decisions are recorded under the delegate's own name |
The Admin Workspace's Access reviews dashboard shows running campaigns, reviews past their due date, undecided lines, and removals not yet confirmed.
Removals
A Remove decision is carried out the way Guided Setup step 11 says: directly, or through a removal request every time, or only when the work is manual. Either way the removal goes to the engine, or to the collection's support group as a ServiceNow task.
- The access shows Pending revoke until the engine confirms the removal or the task is closed complete.
- If a removal fails, the access stays as it was and the campaign waits.
- Cancelling the removal in triage reopens the decision, so the reviewer can decide again.
- Removing one piece of access never removes other access linked to it.
A campaign moves from active to closing when every line is decided, and to complete when every removal is confirmed. Cancel campaign stops a campaign, but removals already sent are not taken back.
Reopen decision on a review line sets it back to not decided. It is not available while the line's removal can still run (cancel the operation first), after the removal is confirmed, or once the campaign has closed.
The evidence pack
When a campaign completes, Warde attaches an evidence pack to it. The pack reports the campaign as it was launched: its scope and reviewer strategy, every line with the person, account, entitlement and how the access was granted, every decision with its reason, who decided and when, and for each removal the engine that ran it, the engine's reference and the time it was confirmed. Lines withdrawn partway through, for example because the source system stopped reporting them, stay in the pack marked as withdrawn.
Select Generate evidence pack on a campaign to produce it again.
Who reviews what
Reviewers see the application, what the access lets someone do, how it was granted, its risk rating, and whether the person has left. They choose Keep or Remove for each line, or for many at once. The user guide describes the reviewer's screen.
| Subject | What Keep and Remove mean |
|---|---|
| Entitlement assignment | Keep or remove that one piece of access |
| Requestable bundle holding | Keep or remove the whole bundle |
| Birthright bundle holding | Keep only. Keeping it brings the person onto the bundle as it is now. Change the joiner rule or the HR details to take it away. |