Skip to main content

Access-review campaigns (GY.C10)

Control mapping: NIST 800-53 AC-2(3) / AU-6, ISO 27001 A.8.7 / A.5.34, SOC 2 CC-6.3 / CC-7.2. This mechanism supports the periodic access-review controls in docs/security-audit/ACCESS_REVIEW_POLICY_DRAFT.md (quarterly campaign cadence). It does not claim the control is met: the procedure around it is yours to run and sign.

What it does​

A tenant admin (a parent user of the tenant, or a platform admin) creates an access-review campaign under /v1/tenant/access-reviews/campaigns. Creating the campaign takes a snapshot of the tenant's current access state into review items:

  • scope=resource_grants — one item per active resource_permissions grant (capability, resource, granted user).
  • scope=all_members — one item per active tenant member.
  • scope=admins_only — one item per tenant admin (parent user).

Each item is signed off inline:

  • Approve (keep) — POST .../items/{id}/approve, optional comment.
  • Revoke — POST .../items/{id}/revoke, comment REQUIRED. Grant items are revoked through the existing permission-revocation path (soft revoke + the normal permission_revoked audit event), so the grant is audited the same way as any manual revocation. Member items revoke all of that member's active resource grants.

Closing the campaign (POST .../campaigns/{id}/close) records the sign-off: who closed it, when, with what comment, and the per-status counts (approved / revoked / pending). Every sign-off, revocation, and close writes an append-only audit row; campaigns and items are status-changed, never hard-deleted (ISO 27001).

Scheduling​

A campaign can be created with schedule_due_at; it stays in scheduled status until the scheduler opens it (snapshotting at open time). The scheduler job access_review_campaigns (15-minute cadence) is gated by the platform setting access_review.schedule_enabled — off by default. With it off, scheduled campaigns simply wait.

Separation-of-duties (SoD) report​

GET /v1/tenant/access-reviews/sod-report is a read-only report of users holding both roles of a configured conflicting pair. Pairs live in the platform setting access_review.sod_role_pairs (default: billing-admin + auditor, tenant-admin + auditor). Role keys: tenant-admin (parent user), billing-admin (parent user or a custom role named billing-admin), platform-admin, auditor (active compliance auditor grant or an auditor custom role). The report names each user's evidence ("via") for both roles so a reviewer can act.

Endpoints (tenant admin only; cross-tenant id → 404)​

Method & pathPurpose
POST /v1/tenant/access-reviews/campaignscreate (+snapshot)
GET /v1/tenant/access-reviews/campaignslist tenant campaigns
GET /v1/tenant/access-reviews/campaigns/{id}detail + items + counts
POST .../items/{id}/approvesign off: keep
POST .../items/{id}/revokesign off: revoke (comment required)
POST .../campaigns/{id}/closeclose = sign-off record
GET /v1/tenant/access-reviews/sod-reportSoD conflict report