Access Reviews Overview
Learn how Probo access reviews connect providers or CSV data as sources, snapshot identities and permissions, and record reviewer decisions.
Access reviews let an organization take a point-in-time snapshot of identities and permissions, record reviewer decisions, and preserve the result of the campaign. Sources can be connected providers or CSV data exported from another system.
How It Works
Section titled “How It Works”- Create one or more access sources.
- Create a campaign and attach the sources that define its scope.
- Start the campaign to fetch and snapshot available access entries.
- Review entries, add flags where useful, and record decisions.
- Complete the campaign after every entry has a decision.
Campaign statistics describe the current review state. The snapshot remains separate from the provider’s live directory, so remediation in a provider does not silently rewrite the decision history.
See Run an Access Review Campaign for the complete console workflow.
What Probo Collects
Section titled “What Probo Collects”For each account in a review, Probo shows the following, wherever the provider exposes it. Fields the provider doesn’t return are left blank.
| Field | What it tells reviewers |
|---|---|
| Name | The account holder’s name (service accounts are marked) |
| The account’s email address | |
| Role | The role(s) the account holds in the provider |
| Admin | Whether the account has administrator access |
| Status | Whether the account is active or disabled |
| MFA | Whether multi-factor authentication is enabled |
| Last login | When the account last signed in or was used |
Connection Methods
Section titled “Connection Methods”- OAuth. When Add Source offers Connect for a provider, Probo sends you to that provider’s consent screen. Availability depends on the provider and your Probo deployment.
- API key or client credentials. You generate a credential on the provider and paste it into Probo. The credential type and required permissions vary, so check the Connector Directory.
- CSV. Paste an exported account list for a system Probo cannot connect to directly. See Create a CSV Access Source.
Access reviews live under Access Reviews in your organization: the Sources tab connects providers, the Campaigns tab runs reviews.
See How Probo Protects Integration Credentials for encryption, access control, and data handling.
Review Boundaries
Section titled “Review Boundaries”Provider APIs expose different fields and may omit MFA, login, status, or role information. A blank value means the source did not provide it; it should not be interpreted as a passing or failing control. Reviewers remain responsible for deciding whether an identity and its access are appropriate.
Recording a decision does not change the account in the provider. Complete revocations and role changes in the source system, then use the campaign record as evidence of the review.