Access-review campaigns (GY.C10)
Control mapping: NIST 800-53 AC-2(3) / AU-6, ISO 27001 A.8.7 / A.5.34,
SOC 2 CC-6.3 / CC-7.2. This mechanism supports the periodic
access-review controls in
docs/security-audit/ACCESS_REVIEW_POLICY_DRAFT.md (quarterly campaign
cadence). It does not claim the control is met: the procedure around
it is yours to run and sign.
What it does
A tenant admin (a parent user of the tenant, or a platform admin)
creates an access-review campaign under
/v1/tenant/access-reviews/campaigns. Creating the campaign takes a
snapshot of the tenant's current access state into review items:
scope=resource_grants— one item per activeresource_permissionsgrant (capability, resource, granted user).scope=all_members— one item per active tenant member.scope=admins_only— one item per tenant admin (parent user).
Each item is signed off inline:
- Approve (keep) —
POST .../items/{id}/approve, optional comment. - Revoke —
POST .../items/{id}/revoke, comment REQUIRED. Grant items are revoked through the existing permission-revocation path (soft revoke + the normalpermission_revokedaudit event), so the grant is audited the same way as any manual revocation. Member items revoke all of that member's active resource grants.
Closing the campaign (POST .../campaigns/{id}/close) records the
sign-off: who closed it, when, with what comment, and the
per-status counts (approved / revoked / pending). Every sign-off,
revocation, and close writes an append-only audit row; campaigns and
items are status-changed, never hard-deleted (ISO 27001).
Scheduling
A campaign can be created with schedule_due_at; it stays in
scheduled status until the scheduler opens it (snapshotting at open
time). The scheduler job access_review_campaigns (15-minute cadence)
is gated by the platform setting access_review.schedule_enabled
— off by default. With it off, scheduled campaigns simply wait.
Separation-of-duties (SoD) report
GET /v1/tenant/access-reviews/sod-report is a read-only report of
users holding both roles of a configured conflicting pair. Pairs
live in the platform setting access_review.sod_role_pairs
(default: billing-admin + auditor, tenant-admin + auditor). Role
keys: tenant-admin (parent user), billing-admin (parent user or a
custom role named billing-admin), platform-admin, auditor (active
compliance auditor grant or an auditor custom role). The report names
each user's evidence ("via") for both roles so a reviewer can act.
Endpoints (tenant admin only; cross-tenant id → 404)
| Method & path | Purpose |
|---|---|
POST /v1/tenant/access-reviews/campaigns | create (+snapshot) |
GET /v1/tenant/access-reviews/campaigns | list tenant campaigns |
GET /v1/tenant/access-reviews/campaigns/{id} | detail + items + counts |
POST .../items/{id}/approve | sign off: keep |
POST .../items/{id}/revoke | sign off: revoke (comment required) |
POST .../campaigns/{id}/close | close = sign-off record |
GET /v1/tenant/access-reviews/sod-report | SoD conflict report |