Access reviews
Access creeps. People change teams, projects end, contractors finish, and the role someone was given eighteen months ago quietly outlives its reason. An access review is the periodic check that catches this: a snapshot of every live role assignment in your organization, reviewed by a named person, with their sign-off recorded permanently.
Lurno produces these snapshots quarterly and gives you a short wizard to review and attest to one — whether you’re satisfying an ISO 27001 control, an internal security policy, or a customer’s due-diligence questionnaire.
What this does
Section titled “What this does”Once a quarter, Lurno snapshots every active role assignment — who holds which role, at which scope, granted when, expiring when — plus a few headline risk counters. That snapshot becomes a report you review and sign. Attesting doesn’t change anyone’s access; it records a judgement, made by a named person on a named date, that the access shown was appropriate. The signature itself lands in the audit log and cannot be edited afterwards.
Before you start
Section titled “Before you start”- You need audit access to open the reports list, and permission to manage audit for the organization to sign one off.
- Have your revocation route ready. The review tells you what to change; you make the change in roles and permissions — see Roles & permissions.
- Know who owns the sign-off. Attesting is a personal statement, so the account that clicks confirm is the account that appears on the record.
How reports are produced
Section titled “How reports are produced”Reports are generated automatically — there is no “start a campaign” button anywhere in the app.
- A scheduled job runs on the 1st of January, April, July and October and snapshots the quarter that just ended.
- It produces one report per organization, plus one platform-wide report.
- Re-running for the same period refreshes that report in place rather than creating a duplicate.
- The generation itself is written to the audit log, so the report’s provenance is traceable.
Plan your review inside the quarter that follows. If you need an off-cycle snapshot, ask Lurno.
Review and sign off a report
Section titled “Review and sign off a report”Reports are split into Open (waiting on attestation) and History (already attested, read-only). Each card shows the period covered, how many assignments it contains, when it was generated, and whether it’s been attested.
- Open Access reviews and find the report under Open.
- Click Review & attest. The wizard opens on step 1.
- Review. Read the four summary counters, then work down the assignment list.
- Click through to Sign-off. Read the statement — “I have reviewed these assignments and confirm they remain appropriate as of [today’s date]” — and add a note if anything needs explaining. Notes are optional and hold up to 4,000 characters.
- Click Confirm review. The report is stamped with your name and the time, moves to History, and an entry is written to the audit log.
If you don’t hold permission to manage audit for that report’s organization, the Review & attest button is disabled with a tooltip explaining why. Already-attested reports stay openable so anyone can read what was signed.
Re-attesting an already-signed report is allowed and overwrites the previous signature — last signature wins — but every attempt is audited, so the earlier one is still traceable.
What the summary counters mean
Section titled “What the summary counters mean”| Counter | What it tells you |
|---|---|
| Active assignments | Every live role grant in scope for this report — the ones scoped to your organization, plus any granted at the Lurno platform level |
| Suspended users | People in your organization whose account is suspended |
| Orphaned users | Accounts with no organization membership and no active role — see Privacy & incident queues |
| Pending deletions | Deletion or anonymization requests for your organization that are still open |
A non-zero orphan or pending-deletion count isn’t automatically a problem, but it’s the first thing an auditor asks about.
One caveat worth knowing before you quote these numbers: the orphan count is measured across the whole platform, not narrowed to your organization. The other three are scoped to the report’s organization.
Reading the assignment list
Section titled “Reading the assignment list”Assignments are sorted oldest grant first, so the longest-held access is at the top. Each row shows the person’s name and email, the role, the kind of scope the grant applies to (platform, organization, group, branch), and when it was granted. Badges flag rows worth a second look:
- Stale — granted more than 12 months ago. Long-held access is inherently higher risk; treat these as candidates to revoke. A count of stale rows also appears above the list.
- Suspended — the person’s account is suspended but the role grant is still live.
- Orphaned — the account has no remaining attachment to any organization.
Stale is measured from the grant date, not from last activity, so a long-serving administrator will show as stale every quarter. That’s expected — the badge prompts a decision, it doesn’t make one.
Revoking access
Section titled “Revoking access”The review is read-and-sign. There is no revoke control inside the wizard, deliberately: removing access is a change to your live configuration and belongs where the rest of role management lives. Work through the flagged rows, revoke what shouldn’t be there in Roles & permissions or on the person’s profile, and then attest. Revocations you make are themselves recorded in the audit log, and the next quarterly snapshot will show the tidied picture.
Team compliance — “My team”
Section titled “Team compliance — “My team””My team is a separate, read-only board covering a different kind of compliance: required training, not access. It shows the people you’re responsible for and where they stand on required programs and courses.
- Four headline numbers: Overdue, Due in 7 days, In progress, Completed.
- Tabs to filter to all rows, overdue, due soon, or completed.
- Rows grouped by person, showing each required item, its state, whether it’s required, whether it’s overdue, and its due date.
The page has no permission gate at all — anyone signed in can open it, and it shows only rows they’re already entitled to see. That’s what makes it usable by line managers, sponsors, and guardians who hold no administrative permission. Large organizations should note the board loads the first 500 rows and shows a notice when it hits that ceiling; narrow the filters to see the rest.
Reference
Section titled “Reference”| Term | What it is |
|---|---|
| Report | A snapshot of one organization’s live role assignments for one quarter |
| Period | The quarter the snapshot covers (start and end dates on the card) |
| Attestation | A named person’s recorded confirmation that the access shown was appropriate |
| Attestation note | Optional free text stored with the signature, up to 4,000 characters |
| Stale assignment | A grant more than 12 months old |
| Orphaned account | An account with no organization membership and no active role |
| Team compliance | The required-training board, shown as My team |
Troubleshooting
Section titled “Troubleshooting”Access reviews says the surface is restricted. Your audit access is scoped to your organization; the reports list currently requires audit access granted at the Lurno platform level. Ask Lurno to enable it.
The list is empty. No snapshot has been generated for your organization yet. The next quarterly run — 1 January, April, July or October — will populate it.
Review & attest is disabled. You can read the report but don’t hold permission to manage audit for the organization it covers. Ask an administrator with that permission to sign, or to grant it to you.
I attested and then spotted a problem. Fix the access itself in roles and permissions, then attest the report again. The new signature replaces the old one on the report, and both attempts remain in the audit log.
Someone shows as stale but their access is correct. Stale simply means the grant is over a year old. Confirm it in your note and move on; the badge is a prompt, not a verdict.