WardeDocs User Guides Admin Guides warde.app

Admin Guides / Access review campaigns

Define a campaign

Set what a campaign reviews, who reviews it, how long reviewers have and how often it runs.

Create a definition

Open Access reviews > Campaign definitions in the Admin Workspace and create one.

FieldWhat to enter
NameEach campaign launched from it is named after it, with the launch date
DescriptionShown to reviewers under the campaign name. Say why the campaign is running and what to weigh.
SubjectEntitlement assignments to review single pieces of access, or Access bundle holdings to review whole bundles. Access that comes with a bundle or role the person holds is reviewed with it, and access an engine gives by its own rules is left to that engine.
Scope conditionWhich access to review: a collection, an entitlement, a group of people, a risk level. Empty reviews all active access.
Bundle scope conditionFor bundle holdings: which bundles. Only holders behind the current version reviews only people left on an older version by a change.
Reviewer strategyLine manager of the access holder, Entitlement owner, Entitlement collection owner, or Access bundle owner
Fallback reviewerRequired. Reviews every line nobody else can.
Due in (days)How long reviewers have, counted from launch. The default is 14.
Justification on revokeReviewers must give a reason when they remove access
Justification on bulk approveReviewers must give a reason when they keep several lines in one action
ActiveInactive definitions neither launch on schedule nor by hand

If the reviewer strategy finds nobody, or would ask someone to review their own access, the line goes to the holder's manager, then to the fallback reviewer.

Scope conditions

The scope condition is built over the access people hold, and always reviews only active access. It can filter on the person, the account, the entitlement and anything on it, such as its collection or risk rating, how the access was granted, when it was granted or expires, and when it was last certified. For bundle holdings, the bundle scope condition filters on the person, the bundle, the version, how it was assigned and when it was last certified.

CampaignSubject and scope
Quarterly review of finance applicationsEntitlement assignments where the entitlement's collection is SAP or Oracle Financials. Line manager. Monthly, repeat every 3.
Six-monthly privileged accessEntitlement assignments where the entitlement's risk rating is High. Entitlement owner. Monthly, repeat every 6.
Access never certifiedEntitlement assignments where last certified on is empty. Line manager. On demand.
People left behind by a bundle changeAccess bundle holdings for the bundles concerned, with Only holders behind the current version ticked. Access bundle owner.

Access your identity system grants by its own rules, and access marked as automated in the identity system, is left out of reviews: the rule decides who holds it, not a reviewer.

What reviewers decide

Reviewers see the application, what the access lets someone do, how it was granted, its risk rating, and whether the person has left. They choose Keep or Remove for each line, or for many at once. The user guide describes the reviewer's screen.

SubjectWhat Keep and Remove mean
Entitlement assignmentKeep or remove that one piece of access
Requestable bundle holdingKeep brings the person onto the bundle as it is now, granting what was added and removing what was taken out. Remove takes away the whole bundle.
Birthright bundle holdingKeep only. Keeping it brings the person onto the bundle as it is now. Change the joiner rule or the HR details to take it away.

Schedule it

RunMeaning
On demandLaunches only when an administrator selects Launch campaign
OnceLaunches once, on the start date
Daily, Weekly, Monthly, AnnuallyRecurring. Weekly uses Day of week; Monthly and Annually use Day of month, and Annually uses Month.

Starting is the date occurrences are counted from; a recurring schedule with no start date never runs. Ending is optional. Repeat every runs every Nth occurrence: Monthly with 3 is quarterly, Weekly with 2 is fortnightly.

Scheduled campaigns start when the Warde campaign scheduler job runs, daily at 06:30 instance time. That run time is the launch time for every campaign on the instance. A definition has one live campaign at a time: a launch, by hand or on schedule, is refused while the last one is still running, because two runs would give the same access to two reviewers.

Warde is a ServiceNow scoped application, x_66256_warde. These guides describe the current release. Questions go to [email protected].

ServiceNow is a trademark of ServiceNow, Inc. SailPoint, IdentityIQ and Identity Security Cloud are trademarks of SailPoint Technologies, Inc. Microsoft and Microsoft Entra are trademarks of the Microsoft group of companies.