LogoLogo
SupportDeveloper Docs
  • Welcome
  • Getting Started
    • Introduction to BalkanID
      • BalkanID Onboarding
      • BalkanID Summary Dashboard
    • Setting Up BalkanID
      • User Role Management
      • Users Entitlements Discovery
      • Employee Data Extraction
      • Application Integration & Entitlement Data Extraction
      • Business Owners for Application Integrations
    • Entitlement Discovery
      • Entitlements Discovery
      • Applications Entitlements Discovery
      • Connection Entitlement Discovery
      • Resource Entitlement Discovery
      • Identities Entitlements Discovery
      • Working with Filters
      • Impact Analysis
    • Access Review Management
      • Access Review Campaigns
      • Performing Access Reviews
      • Campaign dashboard and management
      • Campaign Audit Reporting
      • Access Review Campaign Notifications and Reminders
      • Configuring Integration Specific Multi-Level Review Settings
      • Configuring Multi-Level Review Settings in Campaigns
      • Reviewer Insight Escalation for Campaigns
      • Recurring Campaigns
      • Campaign Escalation
      • Nominate Delegate In Account Preferences
      • Access Review Graphs
      • Access Review Recommendations
    • Access Request Management
      • Creating and Managing Access Requests
        • New User Access Request
        • New Service Account Access Request
        • New Identity Access Request
        • New Connection Access Request
        • New Resource Access Request
        • New SCIM Access Request
    • System Notifications & Automatic Ticket Creation
      • Notification Preferences
      • In-app Notifications
      • Supported Ticketing Systems
    • BalkanID CLI
      • BalkanID Extractor CLI
      • BalkanID API CLI
  • Configurations and Integrations
    • Integrations Overview
    • HRIS Integrations
      • Integrate via Merge
    • Direct Application Integrations
      • Asana Integration Setup
      • Atlassian Confluence Integration Setup
      • Atlassian Jira Application Integration Setup
      • AWS Application Integration Setup
      • AWS Identity Center Integration Setup
      • Bitbucket Integration Setup
      • Box Integration Setup
      • Code Climate Integration SetupPage
      • Datadog Integration Setup
      • Dropbox Integration Setup
      • GitHub Application Integration Setup
      • Gitlab Integration Setup
      • Google Cloud Platform Integration Setup
      • Google Drive Integration Setup Guide
      • Google Workspace Integration Setup
      • Jenkins Integration Setup
      • JumpCloud Integration Setup
      • MariaDB Integration Setup
      • Microsoft Azure and Active Directory (AD) Integration Setup
      • On-Prem Active Directory (AD) Integration Setup
      • Microsoft Office365 Integration Setup
      • MongoDB Integration Setup
      • MySQL Integration Setup
      • Netsuite Application Integration Setup
      • New Relic Integration Setup
      • Okta Application Integration Setup
      • Onelogin Integration Setup
      • OpenVPN Integration Setup
      • Pagerduty Integration Setup
      • Ping Identity Integration SetupPage
      • PostgreSQL Integration Setup
      • Ramp Integration Setup
      • Salesforce Application Integration Setup
      • SAP Integration Setup
      • Sendgrid Integration Setup
      • Sentry Integration Setup
      • Slack Application Integration Setup
      • Smartsheet Integration Setup
      • Snowflake Integration setup
      • Splunk Integration Setup
      • Sumologic Integration Setup
      • Twingate Integration Setup
      • Zoom Integration Setup
    • Manual Uploads
      • Application Entitlement Data
      • Employee Data
      • Mapping Identities to Employees
    • SSO Integrations
      • Ping Identity
      • Okta
      • OneLogin
      • Microsoft
    • Fulfillment Options
    • BalkanID API
  • Playbooks and Webhooks
    • Playbooks Overview
    • Configuring Global Playbooks
    • Configuring Integration Specifc Playbooks
    • Configuring Global Webhooks
    • Configuring Integration Specific Webhooks
    • Automated Employee Data Upload Playbook with AWS Lambda & S3
    • Automated Entitlement Data Upload Playbook with AWS Lambda & S3
  • IAM RISK ANALYZER
    • Findings
    • Current State RBAC
    • IAM Risk & RBAC Analysis Report
  • Insights and Rules
    • Entitlement Rules & Labels
      • Setup Rules and Labels
      • Terminated Employee Label
      • Privileged identity Label
      • Setup privileged identities
    • Entity Insights and Finding Rules
      • Creating entity filters
      • Setup insights using entity filters
      • Setup finding rules using entity filters
  • BalkanID Slackbot
    • Setting up BalkanID Slackbot
    • Access Requests and Access Review Notifications with BalkanID Slackbot
    • Findings (Daily Alert) with BalkanID Slackbot
  • JITPBAC
    • Overview of JITPBAC
    • Purposes
      • Create Purpose
      • Edit Purpose
      • Delete Purpose
      • Filtering Purposes
      • Create User-Purpose Access Request
        • Creating a Request Through the Web App
        • Creating a Request Through the Slackbot
      • Starting & Stopping Assigned Purposes
  • BalkanID Copilot
    • BalkanID Copilot
  • Updates
    • Release Notes
      • Introducing Findings: Prioritize, Act, and Automate Identity Risk Management
      • Action Center as a command hub for identity risk findings
      • Introducing Impact Analysis: Visualize, Understand, and Manage Access
      • In-app Notifications & Notification Preferences
      • Upgrades to RBAC Analyzer
      • Slackbot for Access Requests and Review Notifications
      • Playbooks and Webhooks for enhanced workflow automation
      • Introducing support assistant for BalkanID application for in-app support
      • Scheduling campaigns & multi-level approvals, nomination & delegation of reviews and graph views for
      • Campaign dashboard actions, access reviews by identity, enhanced access requests and entities connec
      • Access Provisioning & Deprovisioning, Email Notifications, Access Reviews & Campaigns Updates and Ne
      • Quickly find what you’re looking for with the new People, Applications, and Identities pages
      • Integrate your HRIS or Identity Provider without exposing sensitive personnel data or powerful admin
      • Quickly find unusual entitlements with Outliers (Early Access)
      • Announcing “Days Since Termination” filter
      • Announcing JumpCloud direct integration
      • Published Access Review Campaigns can now be deleted
      • Easily switch between tenants using the new tenant picker
      • Skip Access Review Campaigns by downloading a PDF report of your Entitlements
      • User account information now available on the Account page
      • Announcing Bulk API (Early Access)
      • Announcing HRIS integration capability with 23 new HRIS integrations
      • Privileged Identity insights help to quickly identify privileged identities
      • Terminated insights help to quickly identify and remediate entitlements held by terminated employees
      • Announcing Azure and Azure Active Directory direct integration
      • Access Review Campaign drafts can now be permanently deleted
  • Terms & Conditions
    • Privacy Policy
    • Terms of Service
    • AI Policy FAQ
    • Trust Center
Powered by GitBook

© 2025 · BalkanID, Inc. | Nothing on the BalkanID website, platform, or services, nor any portion thereof constitutes actual legal or regulatory advice, opinion, or recommendation by BalkanID, Inc.

On this page
  • Introduction
  • Action Center Overview
  • Action Center Detail View
  • 1. Accept Risk
  • 2. Notify
  • 3. Revoke
  • 4. Review
  • 5. Execute Playbook
  • 6. Execute Webhook

Was this helpful?

Export as PDF
  1. Insights and Rules

Action Center

Last updated 8 months ago

Was this helpful?

Introduction

The BalkanID Action Center brings together insights in the form of findings based on two criteria:

(a) BalkanID Admin pre-defined rules and; (b) BalkanID system identified outliers that could have risk implications. These insights help IAM and GRC teams preemptively resolve security or compliance related risks while also providing BalkanID users proactively focus on outlier identities and entitlements that require more attention.

Action Center Overview

The Action Center main page provides a snapshot of all findings, organized by the user (employee name and email) that the finding is related to. This main page also provides the applications that the findings are associated with and the finding labels (SoD - segregation of duties, terminated, privileged or outlier/over-entitled). Once the user clicks on the "view findings" button they are taken to the detailed findings for the user in question. The second icon is the "finding activity" icon that provides the user the logs associated with this finding on what action was taken by whom and when.

Action Center Detail View

The finding detail is organized by the identities associated with the user and aligned to the application where the identity finding was detected. Further, when clicking on the finding description, the user is provided details on the finding in a separate dialogue box. Finally the user is able to dig into the finding status by click on the two action icons. The first icon is the "view finding" icon and provides the following finding detail, finding summary and allows the user to take the following actions on the finding:

1. Accept Risk

"Accept Risk" is one of the five options a user can take on an action center finding.

Once a user selects the "accept risk" option, (s)he is required to fill in the details in the "add explanation" box. Once this is done, the user can press the "accept risk" button as shown above and a confirmation page is shown. The finding in question will move to a "completed" state with all finding details logged in the finding activity page.

2. Notify

"Notify" is one of the five options a user can take on an action center finding.

Once a user selects the "notify" option, (s)he is required to choose the BalkanID user to notify from the drop-down list. Optionally, the user can provide a reason for the notification. Once this is done, the user can press the "Notify" button as shown above and a confirmation page is shown. The finding in question will remain to a "in-progress" state with all finding details logged in the finding activity page till the finding is closed / remediated either via acceptance of risk or an action like "revoke user" or "review user".

The following email is an example of what the notified user will receive:

3. Revoke

"Revoke" is one of the five options a user can take on an action center finding.

Once a user selects the "revoke" option, the user connections associated with the finding will be revoked via the IdP provider in question. The finding in question will move to a "completed" state once user connections have been revoked.

4. Review

"Review" is one of the five options a user can take on an action center finding.

Once a user selects the "review" option, (s)he can edit the name of the pre-populated review, the start/end date of the review (again pre-populated for ease of use) prior to submitting the finding for review. The individual required to perform this review is defined in settings -> application integrations -> setup actions.

Once the review is submitted, the responsible party will be notified via email that they have been assigned a review with all the details mentioned above. The finding in question will move to a "completed" state once the review of the finding has been completed.

5. Execute Playbook

Once a user selects the "execute playbook" option, (s)he can see the actions that will be executed as part of that playbook.

Once the playbook has been executed, the finding will remain in an "in-progress" state till all steps of the playbook have been completed (reviews, revoke etc.)

6. Execute Webhook

"Execute Playbook" is one of the options a user can take on an action center finding. Prior to reviewing this article, read about playbooks .

For an overview on Playbooks and Webhooks, refer .

here
here