Schema Software

Access reviews

User guide · The “Access reviews” tab

An access review (or “recertification”) is where a reviewer confirms each person still needs the access they have. The Access reviews tab runs these on a cadence: pick a scope, decide keep or revoke for each item, sign off as a human certification, and the app applies the revocations for you. Each review is exportable compliance evidence.

An open access review listing each person, the access being reviewed, a Keep / Revoke decision and an optional free-text reason, with Sign off and export controls.
Each item gets a Keep or Revoke decision and, optionally, a reason. Once every item is decided you sign off, then apply the revocations — and export the whole review, reasons included, as evidence.

Running a review, end to end

  1. Select New review and choose a scope:
    • Group membership — recertify who belongs to a group (revoke removes the member).
    • Project access — recertify who can access a project (revoke removes them from the project's role).
    • Inactive seat-holders — recertify inactive users who hold a licence (revoke reclaims the seat).
  2. For a group or project scope, pick the specific group/project. Optionally name the review and set a cadence (one-off, monthly, or quarterly — a repeating review reopens itself when due). Select Create review.
  3. For each item, choose Keep or Revoke (selecting again clears the decision). Keep all decides the rest in one click.
  4. Optionally add a Reason for each decision — a short note saying why. It becomes available once you've chosen Keep or Revoke, and saves when you click away.
  5. When every item is decided, select Sign off review — this records who certified it, by name.
  6. Select Apply N revocation(s). A dialog restates what will change; confirm, and the app revokes the access. Then Export CSV/JSON for evidence and Close the review.

Why the “Reason” column is worth filling in

It's optional, and the review works without it. But it's usually the first thing an auditor reads, because the question they're asking isn't whether access was reviewed — it's why access was kept. A review where every row says Keep and none says why demonstrates that someone clicked through it, not that anyone judged it.

A useful reason is short and points at something outside the app: the business need, the role that requires it, an end date, or a ticket. “Contractor, needed through Q3 (JIRA-4412)” answers the question. “Approved” doesn't.

Reasons are saved with the decision, appear as a Justification column in the CSV/JSON evidence export, and are recorded in the Audit log like any other decision. Clearing a decision clears its reason too.

Reading a review

  • The reviews list shows each campaign's scope, status (In review, Signed off, Executed, Closed), how often it repeats, progress (decided / total), and how many items are marked to revoke.
  • Inside a review, the items table shows each principal, the access being reviewed, its decision/outcome, and the reason recorded for it.
  • A canceled review can be reopened; decisions are preserved.

When a revocation needs you to finish in Jira

Most revocations are applied automatically. But some access — a direct grant to a person, or externally-managed (SCIM) membership — can't be changed by an app. After you apply, a clear banner flags those items as “Revoke in Jira” with step-by-step instructions and a direct link, so nothing is silently left undone.