LogoLogo
SupportDeveloper Docs
  • Welcome
  • Getting Started
    • Introduction to BalkanID
      • BalkanID Onboarding
      • BalkanID Summary Dashboard
    • Setting Up BalkanID
      • User Role Management
      • Users Entitlements Discovery
      • Employee Data Extraction
      • Application Integration & Entitlement Data Extraction
      • Business Owners for Application Integrations
    • Entitlement Discovery
      • Entitlements Discovery
      • Applications Entitlements Discovery
      • Connection Entitlement Discovery
      • Resource Entitlement Discovery
      • Identities Entitlements Discovery
      • Working with Filters
      • Impact Analysis
    • Access Review Management
      • Access Review Campaigns
      • Performing Access Reviews
      • Campaign dashboard and management
      • Campaign Audit Reporting
      • Access Review Campaign Notifications and Reminders
      • Configuring Integration Specific Multi-Level Review Settings
      • Configuring Multi-Level Review Settings in Campaigns
      • Reviewer Insight Escalation for Campaigns
      • Recurring Campaigns
      • Campaign Escalation
      • Nominate Delegate In Account Preferences
      • Access Review Graphs
      • Access Review Recommendations
    • Access Request Management
      • Creating and Managing Access Requests
        • New User Access Request
        • New Service Account Access Request
        • New Identity Access Request
        • New Connection Access Request
        • New Resource Access Request
        • New SCIM Access Request
    • System Notifications & Automatic Ticket Creation
      • Notification Preferences
      • In-app Notifications
      • Supported Ticketing Systems
    • BalkanID CLI
      • BalkanID Extractor CLI
      • BalkanID API CLI
  • Configurations and Integrations
    • Integrations Overview
    • HRIS Integrations
      • Integrate via Merge
    • Direct Application Integrations
      • Asana Integration Setup
      • Atlassian Confluence Integration Setup
      • Atlassian Jira Application Integration Setup
      • AWS Application Integration Setup
      • AWS Identity Center Integration Setup
      • Bitbucket Integration Setup
      • Box Integration Setup
      • Code Climate Integration SetupPage
      • Datadog Integration Setup
      • Dropbox Integration Setup
      • GitHub Application Integration Setup
      • Gitlab Integration Setup
      • Google Cloud Platform Integration Setup
      • Google Drive Integration Setup Guide
      • Google Workspace Integration Setup
      • Jenkins Integration Setup
      • JumpCloud Integration Setup
      • MariaDB Integration Setup
      • Microsoft Azure and Active Directory (AD) Integration Setup
      • On-Prem Active Directory (AD) Integration Setup
      • Microsoft Office365 Integration Setup
      • MongoDB Integration Setup
      • MySQL Integration Setup
      • Netsuite Application Integration Setup
      • New Relic Integration Setup
      • Okta Application Integration Setup
      • Onelogin Integration Setup
      • OpenVPN Integration Setup
      • Pagerduty Integration Setup
      • Ping Identity Integration SetupPage
      • PostgreSQL Integration Setup
      • Ramp Integration Setup
      • Salesforce Application Integration Setup
      • SAP Integration Setup
      • Sendgrid Integration Setup
      • Sentry Integration Setup
      • Slack Application Integration Setup
      • Smartsheet Integration Setup
      • Snowflake Integration setup
      • Splunk Integration Setup
      • Sumologic Integration Setup
      • Twingate Integration Setup
      • Zoom Integration Setup
    • Manual Uploads
      • Application Entitlement Data
      • Employee Data
      • Mapping Identities to Employees
    • SSO Integrations
      • Ping Identity
      • Okta
      • OneLogin
      • Microsoft
    • Fulfillment Options
    • BalkanID API
  • Playbooks and Webhooks
    • Playbooks Overview
    • Configuring Global Playbooks
    • Configuring Integration Specifc Playbooks
    • Configuring Global Webhooks
    • Configuring Integration Specific Webhooks
    • Automated Employee Data Upload Playbook with AWS Lambda & S3
    • Automated Entitlement Data Upload Playbook with AWS Lambda & S3
  • IAM RISK ANALYZER
    • Findings
    • Current State RBAC
    • IAM Risk & RBAC Analysis Report
  • Insights and Rules
    • Entitlement Rules & Labels
      • Setup Rules and Labels
      • Terminated Employee Label
      • Privileged identity Label
      • Setup privileged identities
    • Entity Insights and Finding Rules
      • Creating entity filters
      • Setup insights using entity filters
      • Setup finding rules using entity filters
  • BalkanID Slackbot
    • Setting up BalkanID Slackbot
    • Access Requests and Access Review Notifications with BalkanID Slackbot
    • Findings (Daily Alert) with BalkanID Slackbot
  • JITPBAC
    • Overview of JITPBAC
    • Purposes
      • Create Purpose
      • Edit Purpose
      • Delete Purpose
      • Filtering Purposes
      • Create User-Purpose Access Request
        • Creating a Request Through the Web App
        • Creating a Request Through the Slackbot
      • Starting & Stopping Assigned Purposes
  • BalkanID Copilot
    • BalkanID Copilot
  • Updates
    • Release Notes
      • Introducing Findings: Prioritize, Act, and Automate Identity Risk Management
      • Action Center as a command hub for identity risk findings
      • Introducing Impact Analysis: Visualize, Understand, and Manage Access
      • In-app Notifications & Notification Preferences
      • Upgrades to RBAC Analyzer
      • Slackbot for Access Requests and Review Notifications
      • Playbooks and Webhooks for enhanced workflow automation
      • Introducing support assistant for BalkanID application for in-app support
      • Scheduling campaigns & multi-level approvals, nomination & delegation of reviews and graph views for
      • Campaign dashboard actions, access reviews by identity, enhanced access requests and entities connec
      • Access Provisioning & Deprovisioning, Email Notifications, Access Reviews & Campaigns Updates and Ne
      • Quickly find what you’re looking for with the new People, Applications, and Identities pages
      • Integrate your HRIS or Identity Provider without exposing sensitive personnel data or powerful admin
      • Quickly find unusual entitlements with Outliers (Early Access)
      • Announcing “Days Since Termination” filter
      • Announcing JumpCloud direct integration
      • Published Access Review Campaigns can now be deleted
      • Easily switch between tenants using the new tenant picker
      • Skip Access Review Campaigns by downloading a PDF report of your Entitlements
      • User account information now available on the Account page
      • Announcing Bulk API (Early Access)
      • Announcing HRIS integration capability with 23 new HRIS integrations
      • Privileged Identity insights help to quickly identify privileged identities
      • Terminated insights help to quickly identify and remediate entitlements held by terminated employees
      • Announcing Azure and Azure Active Directory direct integration
      • Access Review Campaign drafts can now be permanently deleted
  • Terms & Conditions
    • Privacy Policy
    • Terms of Service
    • AI Policy FAQ
    • Trust Center
Powered by GitBook

© 2025 · BalkanID, Inc. | Nothing on the BalkanID website, platform, or services, nor any portion thereof constitutes actual legal or regulatory advice, opinion, or recommendation by BalkanID, Inc.

On this page
  • Create a new campaign:
  • Campaign details
  • Filter criteria
  • Include versus Exclude
  • Re-assigning reviewers for a campaign
  • Deleting a campaign
  • Aborting a campaign

Was this helpful?

Export as PDF
  1. Getting Started
  2. Access Review Management

Access Review Campaigns

PreviousAccess Review ManagementNextPerforming Access Reviews

Last updated 3 months ago

Was this helpful?

Campaigns are a group of access reviews created for audit, compliance, or risk remediation purposes. Risk Managers can create access review campaigns to publish, track, and report on a group of access reviews. A campaign can have various states which are described below:

  • Draft - The campaign has not been published yet.

  • Overdue - The campaign has gone beyond the due date for it.

  • In Progress - The campaign has started and has some time before reaching the due date.

  • Completed - All the access reviews within the campaign have been approved/denied.

  • Aborted - The campaign has been prematurely stopped.

Note - For guidance on enabling provisioning and de-provisioning options, please refer to this article: .(Only Administrator can set Fulfillment Options)

Note: Only users with the “Risk Manager” role are able to create campaigns.

Create a new campaign:

  1. Navigate to the Campaigns page from the navigation sidebar.

  2. Click on the "Create new campaign" button.

  3. You will see a screen as shown in the below image. Configure your campaign according to your requirements on the right sidebar. Remember to enter the necessary components - Campaign name, start date and end date.

  4. Once you have configured your campaign, you can either Save campaign as a draft to publish later OR you can Publish campaign. The description for both the operations are given below:

    • Saving Campaign as a draft BalkanID allows risk managers to create a campaign and save it to be published later. Select “Save as a draft” and your progress will be saved, and you can access the campaign later.

    • Publishing a campaign When a campaign is ready to be kicked off, you can "publish" the campaign. This will create access reviews and assign them to the appropriate reviewers in your organization along with sending the appropriate notifications (new reviews, overdue reviews, etc.)

Campaign details

The campaign details section required the following details about the campaign.

Field

Description

Example

Name

The title for the campaign. The name is displayed in campaign reporting.

Q4 2021 Audit

Description

A short description to provide context on why this campaign has been created.

Review of critical systems for Q4 2021

Start date

The intended start date of the campaign.

Nov 1 2021

End date

The target date a risk manager expects the campaign to be completed.

Dec 14 2021

Repetition

You can design a periodic schedule for the campaign to recur based on your requirement and convenience. Clicking on custom in the dropdown for this field will open a dialog box where you can enter the frequency of recurrence.

Every 1 month on the first day Monday.

Escalation

You can create an alert for the access reviews belonging to this campaign to be escalated if they haven't been completed for a certain duration before the due date.

1 week before due date.

Exclude Reviewers with Insight(s)

Segregation of Duties (SoD) - Insight

Filter criteria

The filter criteria is used to select which identities and entitlements will be reviewed.

Filter

Description

Example

Display name

Name of the employee mapped to the identity

Evan Harper

Job Title

Job title of the employee mapped to the identity

Director of Product

Department

Department of the employee mapped to the identity

Product Management

Manager

Direct manager of the employee mapped to the identity

Marty Padilla

Employment type

Employment type of the employee mapped to the identity

Salaried, full-time

Username

Typically a unique identified like an Email address for the identity in question

evan.harper

Applications

Applications which the identity has access to

Amazon Web Services

Connection

Roles / Groups / Policies

Administrator Group

Resources

A resource is an entity you can work with

AWS S3 bucket or EC2 instance

Permissions

A type of access that is granted to a user or group for an object or object property

Read access to an AWS S3 bucket

Insights

A rule that was in place to detect and alert on SoD and Privileged access violations.

SoD Role to detect engineering access to prod environments

Identity Status

The status of the identity.

Inactive/Suspended

Include versus Exclude

The filter criteria has two tabs: Include and Exclude.

  • Include filters add (or include) particular entitlements that match the filter conditions. For example, setting the Application: Jira include filter condition will add all identities and entitlements for the Jira application to the campaign to be reviewed.

  • Exclude filters remove (or exclude) entitlements that match the conditions from the campaign. For example, setting the Department: Operations exclude filter condition will remove all identities and entitlements for those employees whose department is operations from the list to be reviewed.

The include and exclude filter conditions are a combined query. Therefore, combining the two filters above, we would INCLUDE all identities that have access to the Jira application, EXCEPT Identities with employees that work in the Operations department.

Re-assigning reviewers for a campaign

You can re-assign reviewers for access reviews within a campaign. Follow the below steps to re-assign a campaign:

1. Click on the campaign you would like to delete. It will take you to the campaign main page as shown in the below image.

3. Click on Reassign reviewers.

4. You will see a dialog box as shown below. Choose the reviewer whose reviews you would like to reassign to another employee in Current Reviewer. Select the employee you would like to reassign those reviews to.

5. Click on Confirm

Deleting a campaign

You can delete a campaign when it is not longer necessary. Follow the below steps to delete a campaign:

1. Click on the campaign you would like to delete. It will take you to the campaign main page as shown in the below image.

3. Click on Delete.

Aborting a campaign

When a campaign needs to be closed out prematurely (for reasons like remaining reviews can no longer be completed due to management change etc.), it can be "aborted". Only "overdue" and "in-progress" campaigns can be aborted.

Follow the below steps to abort a campaign:

1. Click on the campaign you would like to delete. It will take you to the campaign main page as shown in the below image.

3. Click on Abort.

You to select specific insights that are applied to the identities of reviewers whose evaluations require escalation for an additional level of review from their line manager. To learn more please refer:

2. Click on "" to open a dropdown with actions.

2. Click on "" to open a dropdown with actions.

2. Click on "" to open a dropdown with actions.

Reviewer Insight Escalation for Campaigns
Fulfillment Options