Skip to main content

User Access Lifecycle

The Identity & Access module manages your organization's personnel directory, application inventory, access grants, and review workflows. It provides a complete picture of who has access to what and ensures access remains appropriate through periodic reviews.

Personnel Directory

Access from Identity & Access → Personnel → Directory in the sidebar.

Personnel Directory showing 14 employees in a table with columns for Name, Department, Role, Status, Apps count, Flags, and Actions — employees from departments including Engineering, Clinical Operations, Compliance, IT, Executive, and HR with statuses Active, Terminated, and On Leave, plus Directory and Org Chart tabs

The directory shows all personnel records with sorting, search, and filter controls. Use the All Departments and All Statuses dropdowns to filter the list, or search by name, email, or department.

Personnel Table

ColumnDescription
NameEmployee's full name
DepartmentOrganizational department
RoleJob role
StatusActive, Terminated, On Leave, or Inactive
AppsCount of applications with active access grants
FlagsCompliance flags (missing NDA, overdue training, etc.)
ActionsDelete action

Click any row to open the personnel detail sidecar.

Personnel Detail

The detail sidecar shows:

  • Basic Info — Name, email, employee ID, phone, employment type
  • Organization — Department, role, manager, start/end dates
  • Compliance — Background check status, security training status, NDA signed
  • Access Grants — Applications this person has access to, with access levels

Personnel Statuses

StatusDescription
ActiveCurrently employed and working
InactiveTemporarily not active (leave pending)
TerminatedNo longer with the organization
On LeaveOn approved leave of absence

Org Chart

The Org Chart tab shows a visual hierarchy based on manager relationships. Click any node to open that person's detail panel. The chart is auto-generated from the manager field — no manual layout needed.

Departments & Roles

The sidebar sub-navigation under Personnel includes:

  • Departments — Manage organizational departments
  • Roles — Define job roles for personnel categorization

Identity Provider Sync

Personnel records can be automatically synced from your identity provider (Microsoft 365/Entra ID or Google Workspace). When sync is enabled:

  • New employees are auto-created from the directory
  • Status changes (suspension, deletion) are reflected automatically
  • Fields marked as "IdP-managed" update on each sync cycle (every 24 hours)
  • Manually-edited fields are preserved unless overridden by sync policy
  • Suspended users are auto-escalated to Terminated after a configurable period

Import & Export

  • Import — Bulk import personnel from CSV
  • Export — Download all personnel records as CSV (button shows count)

Applications

Access from Identity & Access → Applications → Inventory in the sidebar.

Applications inventory showing 8 applications (8 active, 0 deprecated) with type filter tabs (All 8, SaaS 6, Internal 1, Infrastructure 0), search bar, criticality filter, and table with columns for Name, Type, Category, Users, Access Levels, Vendor, Criticality, and Actions — applications include AWS Console, CrowdStrike Falcon, Epic EHR, GitHub Enterprise, Microsoft 365, Salesforce Health Cloud, Surescripts Network, and Workday

The application inventory tracks all software and services your organization uses, with type categorization, criticality ratings, and user counts.

Application Table

ColumnDescription
NameApplication name with icon
TypeSaaS, Internal, Infrastructure, or Other
CategoryFunctional category (Security, Engineering, Clinical, HR, etc.)
UsersCount of personnel with access grants
Access LevelsNumber of defined access levels
VendorLinked vendor record
CriticalityCritical, High, Medium, or Low
ActionsDelete action

Type Filters

Filter applications by type using the tab bar: All, SaaS, Internal, Infrastructure.

Application Detail

Click any application to open the detail sidecar showing:

  • Basic Info — Name, type, category, URL, description
  • Security — Data classification, authentication method, SSO connected, MFA required
  • Provisioning — Provisioning method (Manual, SCIM, API, Directory Sync)
  • Access Levels — Defined access tiers with name, description, and risk tier
  • Users — Personnel with active access grants at each level

Access Levels

Each application defines its available access levels (e.g., "Read", "Edit", "Admin"). Each level has:

FieldDescription
NameHuman-readable level name
DescriptionWhat this level permits
Risk TierLow, Medium, High, or Critical

Adding Applications

  • Add Application — Create manually with name, type, category, and criticality
  • From Vendors — Auto-create applications from your vendor inventory

Access Grants

Access grants record who has access to which applications at what level.

FieldDescription
PersonnelWho has the access
ApplicationWhich application
Access LevelWhat level of access (from app's defined levels)
Grant TypeStandard, Exception, or Temporary
StatusActive, Revoked, or Suspended
Granted ByWho approved the access
Granted AtWhen access was granted

Grant Types

TypeDescription
StandardNormal access following standard procedures
ExceptionAccess outside normal policy (requires justification and approval)
TemporaryTime-limited access with automatic expiry

Access Reviews

Access from Identity & Access → Applications → Reviews in the sidebar. Periodic reviews verify that access grants remain appropriate.

Creating a Review

  1. Navigate to Identity & Access → Applications → Reviews
  2. Create a new review with scope (department, application, or organization-wide)
  3. Assign a reviewer and due date
  4. The review generates a list of all grants in scope

Review Workflow

StatusDescription
In ProgressReviewer is examining each grant
SubmittedReviewer has submitted decisions
ApprovedReview is finalized

Review Decisions

For each grant, the reviewer decides:

DecisionDescription
ApproveAccess is appropriate, no change needed
RevokeAccess should be removed
ModifyAccess level should change
DeferDecision deferred to next review

OCR-Based User Extraction

Access reviews support screenshot uploads for applications that don't have API-based user export. Upload a screenshot of the user list, and the platform uses OCR (Amazon Textract) to extract user names and match them against your personnel directory. This identifies:

  • Orphaned accounts — Users in the app who aren't in your directory
  • Excess access — Users with higher access than expected
  • Missing access — Users who should have access but don't

Access Tickets

Access from Identity & Access → Applications → Tickets. Track access provisioning and deprovisioning requests as tickets with status tracking and assignment.