Access reviews (recertification)
Periodically confirm that the right people still have the right access — the evidence auditors ask for (SOC 2, ISO 27001).
How it works
Open a review and Veridenti generates an item per member. Reviewers certify or revoke each one. Decisions are recorded in the tamper-evident audit log, giving you defensible IGA-lite recertification without a separate tool.
Promotions during an open review
If you promote a member to a privileged role while a review is open, they are automatically added to that review for attestation — no need to close it and start a new one. The mid-review grant gets the same certify-or-revoke treatment as everyone else, so a promotion can never slip through an audit window unreviewed.
What if…
- A review shows stale members — that's the point; revoke them and the change is logged.
- Someone was promoted after the review started — they're already in it; the promotion added them automatically.
- You need proof for an auditor — export the audit log; each decision is hash-chained and timestamped.
Was this helpful?