Use Access Review to confirm role assignments and department coverage, Access Permissions to trace the permissions those roles provide, and Self-Approval Activity to review changes applied without an independent approver.

These reports support periodic access reviews and targeted follow-up. They show recorded access and activity but do not change a person’s roles or permissions.

Before you begin

Activity Permission and scope required
Access Review or Access Permissions Review user access
Self-Approval Activity View positions for every included department; employee names also require View employees
Download CSV or Excel Export reports in addition to the report’s viewing permission

Access Review

Use Access Review for a role-assignment summary. It is useful for periodic review and departure or role-change follow-up. The report has no date or department filter and reflects the active access-role assignments included when the run is prepared.

Each row represents one active role assignment, so a member with several roles appears several times. The row includes the member, job title, email, role, permissions supplied by that role, department scope, and last-seen time.

Review each person’s:

  • active built-in and custom access roles;
  • permissions supplied by each role;
  • department coverage for each department-based role;
  • access received through more than one role; and
  • responsibilities that no longer match current work.

The report is a review aid. Remove or change access on the member’s access page after confirming the intended responsibility.

Example: role change review

Morgan moves from a workforce administration role in Operations to an analyst role in Finance.

Use Access Review to confirm the old Operations role assignment and the new Finance role assignment. Remove the old access when it is no longer required, then run the report again to verify the result.

Access Permissions

Use Access Permissions when you need the individual permissions and department coverage that contribute to a member’s access.

The report has no date or department filter. Each row represents one member, active role assignment, permission, and department-scope combination. Organization-wide responsibilities use their organization-wide scope rather than creating a row for every department.

One person can receive the same permission from several roles. For example, both Analyst and Viewer include position viewing. Removing one role does not remove that permission while the other active role still supplies it.

Use this report to answer questions such as:

  • Who can download reports?
  • Who can view protected actual compensation?
  • Who can manage positions in a particular department?
  • Which role gives a person a permission?
  • Does the permission cover one department or all required departments?

Compare the two access reports

Report Best question
Access Review What roles and coverage does each person have?
Access Permissions Which exact responsibilities and departments result from those roles?

Start with Access Review for the person and use Access Permissions to verify the resulting responsibility. Review both before concluding that access is missing or excessive.

Self-Approval Activity

Use Self-Approval Activity to review requester approvals and recorded import approval bypasses without an independent reviewer. The current request workflow does not let a requester approve their own request. A Requester Approval row describes recorded activity to investigate, rather than an available decision option. Follow your organization’s oversight process before deciding whether any listed activity needs follow-up.

Criteria and filters

Choice Required How it works
Start date No When used, includes activity on or after the start of this organization-local date; it must be paired with End date
End date No When used, includes activity through the end of this organization-local date; it must be paired with Start date
Departments No Blank includes all departments you can access; selected departments include the departments beneath them for the report scope

Leaving Start date and End date blank includes captured activity through the report run time. The report returns individual activity rows and does not group results by day, week, month, or year.

This report does not mean every listed action was improper. It identifies work that deserves the organization’s chosen review because the same person initiated and completed the change or an authorized exception bypassed ordinary separation.

For each row:

  1. confirm the person and department;
  2. confirm whether the type is Requester Approval or Import Approval Bypass;
  3. use the reference to open the related request or import evidence;
  4. review the recorded activity time and FTE impact when present;
  5. compare the resulting approved information with policy; and
  6. record any follow-up through the organization’s normal process.

The report does not include the full business reason, changed fields, or resulting position values. Use the reference and activity history for that detail. If you do not have the View employees permission, the user value is restricted while the activity row remains available within your position scope.

Run a periodic review

A useful access review cycle is:

  1. select the review period and authorized audience;
  2. run Access Review and Access Permissions;
  3. review organization-wide roles first;
  4. review protected financial access;
  5. review temporary and departing-user access;
  6. review Self-Approval Activity for the same oversight period;
  7. make approved corrections; and
  8. run the reports again to verify the final result.

Store downloaded access files as protected information. They can reveal responsibilities, departments, and security-sensitive organizational relationships.