Viewing your reviews

Viewing Your Access Reviews

The Access Review Table is your central hub for managing and acting on access reviews. It provides a comprehensive display of all access relationships relevant to your campaigns, showing what entity (Identity or Connection) has access to what other entity (Connection or Resource), with what specific permissions, all within a given application integration.


Exploring Review Details

Every piece of information presented in the review table is designed to be interactive, allowing you to quickly dive into more context:

Viewing entity metadata

To see more information about a user, connection, or resource, click on it's cell in the table. A side panel will open showing additional context pulled directly from the connected application.

Understanding Relationship Permissions

To see all permissions tied to an entitlement, click the value in the Permissions column. This opens a side panel that explains the privileges that the entity has access to within another entity.

Understanding the Access Provider Column

The Access Provider column helps you understand how a user has access to a connection or resource by showing the complete chain of relationships that grants that access. This includes both direct assignments and indirect (nested) access paths through groups or roles.

For example, if a user inherits access through multiple nested groups, the Access Provider column will display the full hierarchy — such as:

User → Group A → Group B → Resource X

This gives reviewers full visibility into what provided the access and through which entities it flows, making it easier to verify if access is appropriate or excessive.

circle-info

To generate this full chain of access for reviews under a campaign, make sure to toggle the Include Nested Entities setting while creating your campaign.


Understanding Review Grouping Options

BalkanID offers two ways to view your reviews, allowing you to choose the best option for your review workflow: Ungrouped and Grouped by Entity.

Ungrouped Reviews

When reviews are Ungrouped, each individual access relationship is displayed as a separate row in the table. This view allows you to approve or deny each access at a granular level, giving you precise control over every entity relationship.

Grouped by Entity Reviews

When reviews are Grouped by Entity, all access relationships associated with a single Identity or Connection are consolidated into one row in the table. This grouping allows you to action upon all reviews associated with that specific entity at one time, streamlining the review process for entities with many accesses.

To see all the individual reviews associated with a grouped entity, simply click on the "Eye" icon in that entity's row. This will open a detailed view showing all underlying granular accesses.


Comments

The Comments panel shows all discussion and notes associated with a review, helping you understand the context behind access decisions.

circle-info

Comments are available only in the Ungrouped view. In Grouped by Entity, open the detailed view to access comments on individual reviews.

Accessing the Comments Panel

To view comments for a review, click the comment icon in the Comments column of the Ungrouped review table. This opens the Comments side panel where you can see all discussion and context related to that review.

Reviews that include comments added during an action (approve, deny, or reassign) may display a visual indicator (such as a red dot) in the Details view to help draw attention to important context.

Viewing and managing comments

Comments for a review appear in the Comments side panel, with the most recent comments shown first.

You can delete your own comments directly from this panel. If there are many comments, use Previous and Next to move through them.

Common use cases

  • Document decisions: Explain why access was approved or denied.

  • Request info: Ask for clarification before deciding.

  • Collaborate: Tag security, compliance, or risk teams for input.

  • Add context: Note temporary access or follow-ups.

  • Audit trail: Keep discussion context next to the review.

Viewing a review's audit log

BalkanID provides a detailed Audit Log for each access review, allowing you to track all decisions and changes made over time. This audit trail is crucial for compliance, understanding decision-making, and troubleshooting.

circle-info

If an Attestation Set was required for the campaign, the audit log will include the attestation questions and the reviewer’s answers alongside the approve/deny action.

The way you access the audit log depends on whether you're in the "Ungrouped" or "Grouped by Entity" view of your reviews.


In Ungrouped View:

When viewing reviews in the Ungrouped format (where each access is a separate row), you can directly access the action log for any specific review:

  • Navigate to the "Details" column for the review row you want to investigate.

  • Clicking on the detail icon in this column will open a sidebar. This sidebar provides comprehensive information about the review, including its full details and a chronological audit log of all actions taken on that specific review.

In Grouped by Entity View:

When reviews are Grouped by Entity, you first need to access the granular details for the entity before viewing individual review action logs:

Last updated

Was this helpful?