WardeDocs Administrators Connectors People using Warde warde.app

Administrator guide

Access reviews

Define and schedule access review campaigns, follow them to the end, and produce the evidence pack.

An access review asks a manager or an owner to confirm that people still need the access they hold. Warde runs reviews as campaigns on your instance. Reviewers decide on the Reviews tab of My Access in your portal, removals go back through the same path as any other removal, and a campaign closes only when every removal is confirmed.

Campaigns are defined and run in ServiceNow. Warde does not import campaigns from SailPoint or another tool.

Before your first campaign

Define a campaign

Open Access reviews > Campaign definitions in the Admin Workspace and create one.

FieldWhat to enter
NameEach campaign launched from it is named after it, with the launch date
DescriptionShown to reviewers under the campaign name. Say why the campaign is running and what to weigh.
SubjectEntitlement assignments to review single pieces of access, or Access bundle holdings to review whole bundles
Scope conditionWhich access to review: a collection, an entitlement, a group of people, a risk level. Empty reviews all active access.
Bundle scope conditionFor bundle holdings: which bundles. Only holders behind the current version reviews only people left on an older version by a change.
Reviewer strategyLine manager of the access holder, Entitlement owner, Entitlement collection owner, or Access bundle owner
Fallback reviewerRequired. Reviews every line nobody else can.
Due in (days)How long reviewers have, counted from launch. The default is 14.
Justification on revokeReviewers must give a reason when they remove access
Justification on bulk approveReviewers must give a reason when they keep several lines in one action
ActiveInactive definitions neither launch on schedule nor by hand

If the reviewer strategy finds nobody, or would ask someone to review their own access, the line goes to the holder's manager, then to the fallback reviewer.

Access your identity system grants by its own rules, and access marked as automated in the identity system, is left out of reviews: the rule decides who holds it, not a reviewer.

Schedule it

RunMeaning
On demandLaunches only when an administrator selects Launch campaign
OnceLaunches once, on the start date
Daily, Weekly, Monthly, AnnuallyRecurring. Weekly uses Day of week; Monthly and Annually use Day of month, and Annually uses Month.

Starting is the date occurrences are counted from; a recurring schedule with no start date never runs. Ending is optional. Repeat every runs every Nth occurrence: Monthly with 3 is quarterly, Weekly with 2 is fortnightly.

Scheduled campaigns start when the Warde campaign scheduler job runs, daily at 06:30 instance time. That run time is the launch time for every campaign on the instance. A definition has one live campaign at a time: a launch, by hand or on schedule, is refused while the last one is still running, because two runs would give the same access to two reviewers.

While a campaign runs

When a campaign launches, Warde freezes its scope, reviewers and rules, creates one review task per reviewer, and emails each reviewer Access review assigned to you. The email links to the review on My Access.

WhenWhat happens
Before the due dateReviewers are reminded the number of days before set in Guided Setup (default 3)
After the due dateThe review is escalated to the reviewer's manager after the days set in Guided Setup (default 3). The manager can complete it.
A reviewer hands it onReassign review moves the whole review to someone better placed, and the hand-over is recorded
A reviewer is on leavePlatform delegates of the reviewer can work it, and decisions are recorded under the delegate's own name

The Admin Workspace's Access reviews dashboard shows running campaigns, reviews past their due date, undecided lines, and removals not yet confirmed.

Removals

A Remove decision is carried out the way Guided Setup step 11 says: directly, or through a removal request every time, or only when the work is manual. Either way the removal goes to the engine, or to the collection's support group as a ServiceNow task.

A campaign moves from active to closing when every line is decided, and to complete when every removal is confirmed. Cancel campaign stops a campaign, but removals already sent are not taken back.

Reopen decision on a review line sets it back to not decided. It is not available while the line's removal can still run (cancel the operation first), after the removal is confirmed, or once the campaign has closed.

The evidence pack

When a campaign completes, Warde attaches an evidence pack to it. The pack reports the campaign as it was launched: its scope and reviewer strategy, every line with the person, account, entitlement and how the access was granted, every decision with its reason, who decided and when, and for each removal the engine that ran it, the engine's reference and the time it was confirmed. Lines withdrawn partway through, for example because the source system stopped reporting them, stay in the pack marked as withdrawn.

Select Generate evidence pack on a campaign to produce it again.

Who reviews what

Reviewers see the application, what the access lets someone do, how it was granted, its risk rating, and whether the person has left. They choose Keep or Remove for each line, or for many at once. The user guide describes the reviewer's screen.

SubjectWhat Keep and Remove mean
Entitlement assignmentKeep or remove that one piece of access
Requestable bundle holdingKeep or remove the whole bundle
Birthright bundle holdingKeep only. Keeping it brings the person onto the bundle as it is now. Change the joiner rule or the HR details to take it away.

Warde is a ServiceNow scoped application, x_66256_warde. These guides describe the current release. Questions go to [email protected].

ServiceNow is a trademark of ServiceNow, Inc. SailPoint, IdentityIQ and Identity Security Cloud are trademarks of SailPoint Technologies, Inc. Microsoft and Microsoft Entra are trademarks of the Microsoft group of companies.