Admin Guides / Access review campaigns
Define a campaign
Set what a campaign reviews, who reviews it, how long reviewers have and how often it runs.
Create a definition
Open Access reviews > Campaign definitions in the Admin Workspace and create one.
| Field | What to enter |
|---|---|
| Name | Each campaign launched from it is named after it, with the launch date |
| Description | Shown to reviewers under the campaign name. Say why the campaign is running and what to weigh. |
| Subject | Entitlement assignments to review single pieces of access, or Access bundle holdings to review whole bundles. Access that comes with a bundle or role the person holds is reviewed with it, and access an engine gives by its own rules is left to that engine. |
| Scope condition | Which access to review: a collection, an entitlement, a group of people, a risk level. Empty reviews all active access. |
| Bundle scope condition | For bundle holdings: which bundles. Only holders behind the current version reviews only people left on an older version by a change. |
| Reviewer strategy | Line manager of the access holder, Entitlement owner, Entitlement collection owner, or Access bundle owner |
| Fallback reviewer | Required. Reviews every line nobody else can. |
| Due in (days) | How long reviewers have, counted from launch. The default is 14. |
| Justification on revoke | Reviewers must give a reason when they remove access |
| Justification on bulk approve | Reviewers must give a reason when they keep several lines in one action |
| Active | Inactive definitions neither launch on schedule nor by hand |
If the reviewer strategy finds nobody, or would ask someone to review their own access, the line goes to the holder's manager, then to the fallback reviewer.
Scope conditions
The scope condition is built over the access people hold, and always reviews only active access. It can filter on the person, the account, the entitlement and anything on it, such as its collection or risk rating, how the access was granted, when it was granted or expires, and when it was last certified. For bundle holdings, the bundle scope condition filters on the person, the bundle, the version, how it was assigned and when it was last certified.
| Campaign | Subject and scope |
|---|---|
| Quarterly review of finance applications | Entitlement assignments where the entitlement's collection is SAP or Oracle Financials. Line manager. Monthly, repeat every 3. |
| Six-monthly privileged access | Entitlement assignments where the entitlement's risk rating is High. Entitlement owner. Monthly, repeat every 6. |
| Access never certified | Entitlement assignments where last certified on is empty. Line manager. On demand. |
| People left behind by a bundle change | Access bundle holdings for the bundles concerned, with Only holders behind the current version ticked. Access bundle owner. |
Access your identity system grants by its own rules, and access marked as automated in the identity system, is left out of reviews: the rule decides who holds it, not a reviewer.
What reviewers decide
Reviewers see the application, what the access lets someone do, how it was granted, its risk rating, and whether the person has left. They choose Keep or Remove for each line, or for many at once. The user guide describes the reviewer's screen.
| Subject | What Keep and Remove mean |
|---|---|
| Entitlement assignment | Keep or remove that one piece of access |
| Requestable bundle holding | Keep brings the person onto the bundle as it is now, granting what was added and removing what was taken out. Remove takes away the whole bundle. |
| Birthright bundle holding | Keep only. Keeping it brings the person onto the bundle as it is now. Change the joiner rule or the HR details to take it away. |
Schedule it
| Run | Meaning |
|---|---|
| On demand | Launches only when an administrator selects Launch campaign |
| Once | Launches once, on the start date |
| Daily, Weekly, Monthly, Annually | Recurring. Weekly uses Day of week; Monthly and Annually use Day of month, and Annually uses Month. |
Starting is the date occurrences are counted from; a recurring schedule with no start date never runs. Ending is optional. Repeat every runs every Nth occurrence: Monthly with 3 is quarterly, Weekly with 2 is fortnightly.
Scheduled campaigns start when the Warde campaign scheduler job runs, daily at 06:30 instance time. That run time is the launch time for every campaign on the instance. A definition has one live campaign at a time: a launch, by hand or on schedule, is refused while the last one is still running, because two runs would give the same access to two reviewers.