Skip to content

Products

Compliance Officer Service Expert-led compliance, end to end Compliance Portal Share security documents securely Open-source platform Deploy Probo on your own infrastructure

Resources

Probo stories How teams get compliant with Probo Blog Ideas and guidance from the Probo team Guides & tools Practical compliance guides and free tools Love from Customers What customers say about working with Probo Changelog Latest product updates Download Get the Probo Agent

Company

About The people and vision powering Probo Careers Join the team building Probo Brand assets Official logos and visual resources Security Review our security and compliance posture
Overview Understand Probo and its core concepts Product Explore Probo's GRC capabilities Developers Explore GraphQL, CLI, MCP, n8n, and webhooks Deployment Probo Cloud, self-hosting, and configuration

Explore

GitHub Explore our open-source compliance tools

Access Reviews Overview

Learn how Probo access reviews connect providers or CSV data as sources, snapshot identities and permissions, and record reviewer decisions.

View as Markdown

Access reviews let an organization take a point-in-time snapshot of identities and permissions, record reviewer decisions, and preserve the result of the campaign. Sources can be connected providers or CSV data exported from another system.

  1. Create one or more access sources.
  2. Create a campaign and attach the sources that define its scope.
  3. Start the campaign to fetch and snapshot available access entries.
  4. Review entries, add flags where useful, and record decisions.
  5. Complete the campaign after every entry has a decision.

Campaign statistics describe the current review state. The snapshot remains separate from the provider’s live directory, so remediation in a provider does not silently rewrite the decision history.

See Run an Access Review Campaign for the complete console workflow.

For each account in a review, Probo shows the following, wherever the provider exposes it. Fields the provider doesn’t return are left blank.

Field What it tells reviewers
Name The account holder’s name (service accounts are marked)
Email The account’s email address
Role The role(s) the account holds in the provider
Admin Whether the account has administrator access
Status Whether the account is active or disabled
MFA Whether multi-factor authentication is enabled
Last login When the account last signed in or was used
  • OAuth. When Add Source offers Connect for a provider, Probo sends you to that provider’s consent screen. Availability depends on the provider and your Probo deployment.
  • API key or client credentials. You generate a credential on the provider and paste it into Probo. The credential type and required permissions vary, so check the Connector Directory.
  • CSV. Paste an exported account list for a system Probo cannot connect to directly. See Create a CSV Access Source.

Access reviews live under Access Reviews in your organization: the Sources tab connects providers, the Campaigns tab runs reviews.

See How Probo Protects Integration Credentials for encryption, access control, and data handling.

Provider APIs expose different fields and may omit MFA, login, status, or role information. A blank value means the source did not provide it; it should not be interpreted as a passing or failing control. Reviewers remain responsible for deciding whether an identity and its access are appropriate.

Recording a decision does not change the account in the provider. Complete revocations and role changes in the source system, then use the campaign record as evidence of the review.