**Access Review** gives you one list of everything that holds access in your subscription: the subscription itself, its users, services, groups and API tokens. Structurell flags anything that looks broad or out of date, so you can tidy up access regularly or produce evidence for an audit. It's on **Account → Access → Access Review**.

## Before you start

**Access Review** is for subscription administrators. The list keeps itself up to date: Structurell rebuilds it shortly after access changes, and again every hour, so you don't need to generate it. The **Refreshed** column shows when each row was last rebuilt.

## The summary tiles

Four tiles sit above the list:

- **Subjects** is the number of rows in the review.
- **Active** counts rows whose status is enabled, active or trial.
- **Inactive** counts every other row, such as disabled users or expired tokens.
- **Flagged** counts rows with at least one indicator.

Select **Active**, **Inactive** or **Flagged** to filter the list to those rows.

## What's in the list

Each row is a subject. The **Type** column says what kind:

- **Subscription** is your subscription as a whole.
- **User** is a person with access to the subscription. Their status is their membership status.
- **Service** is a service your subscription uses.
- **Group** is a permission group. See [Teams and groups](/account-and-access/teams-and-groups).
- **API Token** is a token created on **Account → Organisation → API Tokens**. Its status is **Active** or **Expired**. See [API tokens](/account-and-access/api-tokens).

The **Permissions** column counts the permissions the subject holds. For a user, this counts only permissions given to them directly, not those they get through groups. For a service, it counts the permissions granted in that service.

## What the indicators mean

The **Indicators** column highlights things worth checking.

- **Broad access** means the subject can do a lot. A user shows it if they're a subscription administrator, hold 20 or more permissions, or have full access to a feature. A group or API token shows it at 20 or more permissions or scopes, or when it includes full access.
- **Disabled access** means the user's account, or their access to this subscription, is disabled.
- **Stale user** means the user's account record hasn't changed in more than 90 days.
- **Orphan subscription** means the subscription has no users.
- **Expired token** means an API token has passed its expiry date.
- **Stale token** means an API token was created more than 30 days ago and has never been used.

An indicator isn't necessarily a problem. Administrators always show **Broad access**, for example. Use the indicators to decide what to look at.

## Filter the list

Use the table's filters to narrow the list, for example to one **Type**, one status, or subjects with a particular indicator. Choosing more than one indicator shows rows that have any of them.

## Export the review

1. Filter the list to the rows you want, or leave it unfiltered to export everything.
2. Select the download button (**Download filtered results**) below the list.
3. Choose **CSV**, **JSON** or **XML**.

You'll see "Export is queued. You will receive an email when it is ready." The file arrives by email and includes the rows that match your filters.

## Act on what you find

The review is read-only. To change something, go to the page that manages it:

- Change a user's access or remove them on **Account → Access → Users**. See [Users, teams, groups and permissions](/account-and-access/users-teams-groups-and-permissions).
- Narrow a group's permissions on **Account → Access → Groups**.
- Edit, rotate or revoke a token on **Account → Organisation → API Tokens**. See [API tokens](/account-and-access/api-tokens).

After you make a change, the review catches up within a few minutes.

## Related articles

- [Users, teams, groups and permissions](/account-and-access/users-teams-groups-and-permissions)
- [API tokens](/account-and-access/api-tokens)
- [Audit and activity logs](/account-and-access/audit-and-activity-logs)