Scheduling identity access reviews

2023-07-03Last updated

To ensure security compliance and audit readiness, you can set up identity access reviews to occur at scheduled intervals. These identity access reviews are performed based on a list of selected roles.

Before you begin

  • Make sure that the roles to be reviewed have already been defined.
  • Make sure that all the required identities have been associated with the correct roles.

What you should know

  • Only an account administrator can schedule identity access reviews.
  • For Identity access reviews, only Yearly schedules are supported.
  • You can schedule up to five identity access reviews at a time, and each review can include a maximum of 20 roles.
Best Practice: Schedule your identity access reviews so that they are automatically triggered before corporate audits or site safety checks to ensure your security compliance and audit readiness.

Procedure

  1. From the homepage, click Organization > Access reviews .
  2. Click Schedule access review.
  3. In the Select review type dialog, select Identity access review.
    Select review type dialog in Genetec ClearID™ with identity access review highlighted.
  4. In the Identity access review schedule dialog, select the options that you require.
    1. Enter a Name for your identity access review.
      For example, You might enter Contractor access review for electricians or Data center identity access review for your direct reports that need access to a data center.
    2. Select the Trigger identity reviews options that you require.
      • Select the day and month that you want the identity access review scheduled.
      • Select the time that you want the identity access review scheduled.
      Note: The time shown in the Identity access review schedules dialog options and all scheduled review times use the UTC time zone.
    3. Select the Roles that you want to include in your Identity access review.
      Identity access reviews will be generated for all identities in that role (active and inactive status). Inactive identities are clearly identified in the review.
    4. (Optional) If you selected Yearly, in the Notes field, you can add more details as needed.
      The Notes field is used to enter more detailed information about the identity access review. This field is typically used when a supervisor performs security reviews. For example, an ISO 27001 review or a SOC 1 or SOC 2 audit report.
    The following example shows an identity access review for Electrical contractors role scheduled to occur Yearly, on the first day of January at 12:00.
    Figure 1. Identity access review (yearly access reviews)
    Identity access review schedule dialog in ClearID showing electrical contractors yearly schedule example.
  5. Click Create.
  6. (Optional) Click an identity access review in the list to see the schedule details.
    1. Click Go to access reviews report to display all access reviews.
Your identity access reviews have now been scheduled.

Example

After you finish

Do the following to complete your access reviews when required: