Access and activity reports
Review who can see and change information, and find changes made without a separate approval.
Updated September 26, 2026
In this article
Use access reports to see who can do what in your organization. Access Review lists assigned roles and departments; Access Permissions shows the tasks those roles allow. Self-Approval Activity helps you review matching decisions made without an independent approver.
These reports support periodic access reviews and targeted follow-up. They show recorded access and activity but do not change a person’s roles or permissions.
Before you begin
| To do this | You need |
|---|---|
| Access Review or Access Permissions | Review user access |
| Self-Approval Activity | View positions for every included department; employee names also require View employees |
| Download CSV or Excel | the matching export permissions in addition to the report’s viewing permission |
Access Review
Use Access Review for a role-assignment summary. It is useful for periodic review and departure or role-change follow-up. The report has no date or department filter and reflects the retained access-role assignments included when the run is prepared.
Each row represents one retained role assignment, so a member with several current or former roles appears several times. The row includes the member, job title, email, role, declared permissions, effective permissions, assignment status, expiry and revocation dates, departments, and when the person was last seen in FTE Tree.
Expired, revoked, or disabled assignments remain visible as evidence and show no effective permissions. A disabled account, membership, role, or scope prevents that assignment from granting access. Making a role unavailable for new assignments does not disable existing assignments. Effective permissions include the matching viewing permissions provided by management access.
Review each person’s:
- active built-in and custom access roles;
- permissions supplied by each role;
- department coverage for each department-based role;
- access received through more than one role; and
- responsibilities that no longer match current work.
The report is a review aid. Remove or change access on the member’s access page after confirming the intended responsibility.
Example: role change review
A separate Evergreen Health practice user moves from a Workforce manager role in Outpatient Services to an Analyst role in Inpatient Services.
Use Access Review to confirm the old Outpatient Services role assignment and the new Inpatient Services role assignment. Remove the old access when it is no longer required, then run the report again to verify the result.
Access Permissions
Use Access Permissions to see the individual tasks a person is allowed to do and the departments where they can do them.
This report has no date or department filter. Read a row as one declared or implied permission associated with a retained role assignment for the departments shown. Check Permission applies and Assignment status before treating the row as current access. Expired, revoked, and disabled assignments remain visible without granting access. A person can therefore appear on many rows. An organization-wide task such as billing is shown for the organization, rather than repeated once for every department.
One person can receive the same permission from several roles. For example, both Analyst and Viewer include position viewing. Removing one role does not remove that permission while the other active role still supplies it.
Use this report to answer questions such as:
- Who can download reports?
- Who can view protected actual compensation?
- Who can manage positions in a particular department?
- Which role gives a person a permission?
- Does the permission cover one department or all required departments?
Compare the two access reports
| Report | Best question |
|---|---|
| Access Review | Which roles and departments can each person use? |
| Access Permissions | Which exact responsibilities and departments result from those roles? |
Start with Access Review to see the person’s roles. Then use Access Permissions to see what those roles let them do and where. Read both before deciding that something is missing or that the person has too much access.
Self-Approval Activity
Use Self-Approval Activity to review requester approvals and recorded import approval bypasses without an independent reviewer. The current request workflow does not let a requester approve their own request. A Requester Approval row describes recorded activity to investigate, rather than an available decision option. Follow your organization’s oversight process before deciding whether any listed activity needs follow-up.
Criteria and filters
| Choice | Required | How it works |
|---|---|---|
| Start date | No | When used, includes activity on or after the start of this organization-local date; it must be paired with End date |
| End date | No | When used, includes activity through the end of this organization-local date; it must be paired with Start date |
| Departments | No | Blank includes all departments you can access; selected departments include the departments beneath them for the report scope |
Leaving Start date and End date blank includes captured activity through the report run time. The report returns individual activity rows and does not group results by day, week, month, or year.
A listed action is not automatically a mistake. Review it because the person who requested the change also completed it, or because an authorized import changed approved information without the ordinary request approvals.
For each row:
- confirm the person and department;
- confirm whether the type is Requester Approval or Import Approval Bypass;
- use the reference to open the related request or import;
- review the recorded activity time and FTE impact when present;
- compare the resulting approved information with policy; and
- record any follow-up through the organization’s normal process.
The report does not include the full business reason, changed fields, or resulting position values. Use the reference and activity history for that detail. If you do not have the View employees permission, the user value is restricted while the activity row remains available for positions you can view.
Run a periodic review
A useful access review cycle is:
- select the review period and authorized audience;
- run Access Review and Access Permissions;
- review organization-wide roles first;
- review protected financial access;
- review temporary and departing-user access;
- review Self-Approval Activity for the same oversight period;
- make approved corrections; and
- run the reports again to verify the final result.
Store downloaded access files as protected information. They can reveal responsibilities, departments, and security-sensitive organizational relationships.
Optional practice: check who can do what
Use prepared practice records for this exercise. Follow its setup instructions before making changes.
- Run Access Review for the people doing the walkthrough. Read their assigned roles and departments.
- Run Access Permissions to see the tasks those roles actually allow.
- Change a separate practice role assignment, then run new reports and compare.
- Run Self-Approval Activity for an appropriate period and inspect any matching decisions.
More than one role can allow the same task. Removing one may leave another that still grants access. Use the reports together to explain that result.
An empty Self-Approval Activity report is correct when there is no matching activity. Do not make a prohibited decision just to produce a row. Keep downloaded access reports with people authorized to read them. See roles and permissions for corrections.
Practice each access and activity report
Continue the report lesson in the administration practice organization. Compare access-report rows with the member’s current roles and department coverage. For activity, open the referenced request or import to understand what happened. Keep any permitted download with people authorized to review that information.
31. Access Review
Question: Does each person have the right access?
Access: Review user access. Downloading also requires Export organization information.
Prepare: Give one practice member the Department requester role for Outpatient Services and another the Viewer role for Inpatient Services. Each row describes access through the person’s role assignment.
Run: Open Reports, choose Access Review, and enter these filters: No date or department filter. Choose CSV, Excel (.xlsx), or On-screen summary, run the report, and wait for it to finish.
Check: Find the intended role and departments for each person. Neither role grants protected employee pay. Add an intentionally excessive practice role only under an instructor’s direction, identify it in a new report, then remove it and rerun. The report itself grants no access.
32. Access Permissions
Question: Which permission comes from which role?
Access: Review user access. Downloading also requires Export organization information.
Prepare: Use the same two users as Access Review. Each row shows a declared or implied permission associated with a role assignment for the departments displayed, with its current effectiveness and assignment status.
Run: Open Reports, choose Access Permissions, and enter these filters: No date or department filter. Choose CSV, Excel (.xlsx), or On-screen summary, run the report, and wait for it to finish.
Check: Find the requester’s position-management/request permissions and the viewer’s viewing permissions. Neither should have Manage actual compensation. If a user holds two roles providing the same permission, removing only one role may leave that permission available; compare the remaining row.
33. Self-Approval Activity
Question: Which changes happened without a separate ordinary review?
Access: View positions. Downloading also requires Export positions.
Prepare: Use instructor-prepared history with an ordinary independently approved request and a permitted import that changed approved position information outside the ordinary request path. Each row identifies an included approval event or import change.
Run: Open Reports, choose Self-Approval Activity, and enter these filters: Use the date range containing the prepared activity; department is optional. Dates filter recorded approval activity. Choose CSV, Excel (.xlsx), or On-screen summary, run the report, and wait for it to finish.
Check: Find the import event and its responsible person, date, and record reference. An ordinary independently approved request should not be mistaken for self-approval. If a supplied historical self-approval example exists, explain its recorded reason. Do not try to bypass current approval controls to manufacture an event. Count unique request references when reviewing request totals; multiple events can describe the same request.