Article

Access review

Check who and what has access to your subscription, spot risky or stale access, and export the results.

Access Review gives you one list of everything that holds access in your subscription: the subscription itself, its users, services, groups and API tokens. Structurell flags anything that looks broad or out of date, so you can tidy up access regularly or produce evidence for an audit. It's on Account → Access → Access Review.

Before you start

Access Review is for subscription administrators. The list keeps itself up to date: Structurell rebuilds it shortly after access changes, and again every hour, so you don't need to generate it. The Refreshed column shows when each row was last rebuilt.

The summary tiles

Four tiles sit above the list:

  • Subjects is the number of rows in the review.
  • Active counts rows whose status is enabled, active or trial.
  • Inactive counts every other row, such as disabled users or expired tokens.
  • Flagged counts rows with at least one indicator.

Select Active, Inactive or Flagged to filter the list to those rows.

What's in the list

Each row is a subject. The Type column says what kind:

  • Subscription is your subscription as a whole.
  • User is a person with access to the subscription. Their status is their membership status.
  • Service is a service your subscription uses.
  • Group is a permission group. See Teams and groups.
  • API Token is a token created on Account → Organisation → API Tokens. Its status is Active or Expired. See API tokens.

The Permissions column counts the permissions the subject holds. For a user, this counts only permissions given to them directly, not those they get through groups. For a service, it counts the permissions granted in that service.

What the indicators mean

The Indicators column highlights things worth checking.

  • Broad access means the subject can do a lot. A user shows it if they're a subscription administrator, hold 20 or more permissions, or have full access to a feature. A group or API token shows it at 20 or more permissions or scopes, or when it includes full access.
  • Disabled access means the user's account, or their access to this subscription, is disabled.
  • Stale user means the user's account record hasn't changed in more than 90 days.
  • Orphan subscription means the subscription has no users.
  • Expired token means an API token has passed its expiry date.
  • Stale token means an API token was created more than 30 days ago and has never been used.

An indicator isn't necessarily a problem. Administrators always show Broad access, for example. Use the indicators to decide what to look at.

Filter the list

Use the table's filters to narrow the list, for example to one Type, one status, or subjects with a particular indicator. Choosing more than one indicator shows rows that have any of them.

Export the review

  1. Filter the list to the rows you want, or leave it unfiltered to export everything.
  2. Select the download button (Download filtered results) below the list.
  3. Choose CSV, JSON or XML.

You'll see "Export is queued. You will receive an email when it is ready." The file arrives by email and includes the rows that match your filters.

Act on what you find

The review is read-only. To change something, go to the page that manages it:

  • Change a user's access or remove them on Account → Access → Users. See Users, teams, groups and permissions.
  • Narrow a group's permissions on Account → Access → Groups.
  • Edit, rotate or revoke a token on Account → Organisation → API Tokens. See API tokens.

After you make a change, the review catches up within a few minutes.

Related articles