Skip to main content
User access reviews are in Beta.
A user access review (UAR) lets you certify that users still need the access they have. You define what to review, Serval assigns reviewers, and each reviewer certifies, denies, or skips every account and role grant in scope. When the review is done, you revoke the access that was denied. UARs produce access-certification evidence for SOC 2, ISO 27001, and similar audits.

How a UAR works

A UAR moves through four stages:
  • Draft: you’re still setting up the details and scope.
  • Prepared: Serval has taken a snapshot of every grant in scope and assigned reviewers. The UAR is ready to launch.
  • Running: assigned reviewers are working through their tasks and recording decisions.
  • Completed: every item has a decision, or the owner ended the review. You can then revoke denied access.
Two roles are involved:
  • The review owner creates and runs the review. Owning a review requires a Manager or org admin role.
  • Reviewers are assigned to individual grants and record decisions. Any member of the organization can be assigned as a reviewer.

Create a UAR

From Access → Access Reviews, click New Review. The setup is a three-step wizard, and Serval saves your progress as you go.

Step 1: Details

  • Enter a Review name (for example, “SOC 2 Quarterly Review”) and an optional Description of the review purpose.
  • Select the Target completion date you want the review finished by. Serval uses it to schedule reminders.
  • Set the Review policy to define how the UAR runs: reviewer steps, whether comments are required on decisions, and whether people can review their own access. You have two options:
    • Leave it on None — Serval defaults to have the review owner review every item with comments optional.
    • Pick a policy your team has created, or create a new one. For more information, see Review policies.
  • Optionally, under AI insights, turn on Generate AI insights to have Serval suggest a decision for each task after launch. For more information, see AI insights.
New Access Review wizard on the Details step, showing Review name, Description, Target completion date, and a Review policy set to None — Serval defaults

Step 1 of the New Access Review wizard: name the review, set a target completion date, and choose a review policy

Step 2: Scope

Your scope filters down the grants that will be reviewed. Choose one of two scope options, then click Configure scope:
  • Manual scope: hand-pick the teams, applications, resources, and roles to review.
  • Tag-based scope: review everything carrying the tags you select within a single team.
Scope step with Manual scope selected and one application added

Manual scope: hand-pick the applications, resources, and roles to review

Scope step with Tag-based scope selected, a tag applied, and the matching applications listed

Tag-based scope: review everything carrying the tags you select within one team

Reviews cover the grants Serval already knows about. If Serval doesn’t automatically track who has access to an application, import the current grants first so they’re in scope. Open the application, go to its Access Management view, open the ⋯ (more actions) menu, and choose Import grants from a file. Upload either a CSV export (up to 15 MiB and 500,000 rows) or a PNG, JPEG, or WebP screenshot of the application’s members list (up to 10 MiB). For a CSV, map each row’s account and role; for a screenshot, Serval reads the accounts, names, roles, and statuses it shows. Review the resulting rows, then commit. Past imports are listed under the application’s Grant imports settings.

Step 3: Prepare and launch

When you continue, Serval prepares a point-in-time snapshot of every account-and-role grant that matches your scope and assigns reviewers to each one based on your review policy. If access changes, those changes aren’t reflected in the snapshot until you prepare a new one. Click Back to return to the scope step, adjust the details or scope, and click Prepare review again. If the scope changed, Serval asks you to confirm and then replaces the earlier snapshot, including any reviewer changes you made to it. If the scope didn’t change, you return to the same prepared review. The prepared list shows each Account, the Role it holds, and the assigned Reviewers.
Drafts and prepared-but-unlaunched reviews are saved to your team, so you can continue setting up a review, or click Back to re-scope it, from any browser until it launches.
Every grant must have at least one reviewer per step before you can launch. When everything is assigned, click Launch Test.
Prepare step listing the prepared account-role grants with assigned reviewers

Step 3: the prepared snapshot of account-and-role grants and their reviewers, ready to launch

Review policies

A review policy defines the way in which a UAR runs: who reviews each grant, whether reviewers must comment, and whether people can review their own access. Review policies are managed under Settings → Review Policies. You can access the review policy creation flow in two different locations:
  • When setting the Review policy in the new UAR creation flow, click + Create policy
  • Navigate to Settings → Review Policies and click + Create policy
To create the policy, enter the following information:
  • Policy Name and Policy Description: a name and a one-line note about when to use the policy.
  • Require comments on decisions (Yes / No): whether a reviewer must add a justification with every decision.
  • Allow self-review (Yes / No): whether a reviewer can decide on their own access.
Then define the reviewer steps that set who reviews, in order. Click Create policy to save. A review pins the policy it was prepared with, so later edits only affect future reviews. You can mark one policy as your team’s default. When a review uses None (the Serval default), the review owner reviews every grant, comments are optional, and self-review is allowed.
Create review policy dialog with Policy Name, Require comments on decisions, Allow self-review, and reviewer steps

The Create review policy dialog: comment and self-review rules, plus the reviewer steps

Complete a UAR (reviewers)

Reviewers work from the My pending tasks tab of a running UAR. For each grant, choose one decision:
  • Certify: the access is still appropriate. Keep it.
  • Deny: the access is no longer justified. Mark it for revocation.
  • Skip: don’t make a decision on this grant.
My pending tasks tab showing grants with Certify, Deny, and Skip actions per row

A reviewer's My pending tasks: certify, deny, or skip each grant

Comments are optional unless the review’s policy requires them, in which case you, the reviewer, must add a comment justifying the decision before it’s recorded. Reviewers are reminded automatically: 7 days before the due date, 1 day before, on the due date, and weekly while overdue. Reminders reach reviewers in Slack, Microsoft Teams, and email.

Manage a UAR (review owners)

The review detail page gives the owner a full view through several tabs:
  • All review tasks: every grant, its reviewers, and its Final decision (Pending, Certified, Denied, or Skipped).
  • My pending tasks: grants awaiting your own decision.
  • Submitted: decisions already recorded.
  • Configuration: the review’s scope, its pinned policy, its notification settings, and the Generate AI insights toggle.
  • Reports: generate and download the audit export (see Reports).
The grant list on All review tasks and My pending tasks has three views. List is a flat, paged table. By app nests grants under each application and resource. By user nests grants under each person, so you can see every role one account holds across the review and how many of their grants are already decided. Expand a person to work through their grants, or select the whole group at once. Use All reviewers on All review tasks to narrow the grant list to one or more assigned reviewers. The control shows who is selected, and the progress summary updates to match the filtered list. Clear filters appears next to the filters whenever any filter or search is active and resets all of them at once. If a reviewer has been deactivated while they still hold review items, a banner above the list says so. Show their items on that banner applies the reviewer filter to the deactivated reviewers found in the rows loaded so far, so you can reassign the affected grants. Owners have extra controls:
  • Override decisions: change a reviewer’s decision on any grant.
  • End review: finish a review before every item is decided. You choose whether to skip the remaining items or deny them. You can also reopen or cancel a review.
All review tasks tab showing accounts, roles, reviewers, and Final decision status, with an Override decisions control

The review owner's All review tasks view, with each grant's final decision and Override decisions

AI insights

AI insights are opt-in per review and off by default. A review with the toggle off runs exactly as described above.
When Generate AI insights is on, Serval generates a suggestion for each task once the review launches: a suggested action, a one-line summary, a set of insight bullets, and a suggested comment. Suggestions are advice. Nothing is recorded until a reviewer acts on the task. Suggestions are built only from the access data Serval already holds for the grant: how and when it was granted, the business justification and messages on the original access request, the last sign-in to the application, whether the account or the person is deactivated, how many peers under the same manager or in the same department hold the same role, and the decision an earlier review recorded on the same grant.

Turn on AI insights

  • When you create the review: on the Details step, under AI insights, turn on Generate AI insights. The launch screen confirms that AI insights will be generated for every task after launch.
  • On a running review: open the Configuration tab and turn on the same toggle. Serval asks you to confirm, because generation starts for every open task.
Generation runs once after launch and isn’t re-run. The Configuration tab shows progress while insights are generated and the number of tasks with insights when it finishes. Turning the toggle off hides every suggestion, including ones already generated. Turning it back on generates insights only for tasks that don’t have one yet.

Suggested actions

Each task gets one of three suggestions:
  • Certify: the signals support keeping the access.
  • Revoke: the signals point to removing the access. Accepting it records a Deny decision.
  • Flagged: the signals are mixed or too thin to suggest a decision. A flagged task has no suggested comment and needs your own decision.

Review with AI insights

  • Insight column: a one-line summary for each task. A task whose insight hasn’t been generated yet shows a dash.
  • Accept suggestion: the decision button highlights the suggested action. Click Accept suggestion to record it with the suggested comment as your justification, or open the decision dialog to edit the comment first. If the review’s policy requires comments, the suggested comment satisfies it — on the rare task that has none, record your own.
  • Insights: expand a task to read the insight bullets and the Suggested comment. Green bullets support keeping the access, red bullets argue for removing it, and the rest add neutral context.
  • Current access: the expanded task also lists the other applications the person currently has access to. View all opens the full list.
  • Filter by suggestion: the All suggestions filter narrows the table to the tasks Serval suggested to Certify or Revoke, or Flagged.
  • Accept in bulk: select tasks and click Accept suggestions to accept every selected suggestion at once. Flagged tasks and tasks without an insight are skipped and stay selected.
A decision made by accepting a suggestion is marked Accepted AI suggestion on the task’s status, so the audit trail shows which decisions were AI-assisted.

Decisions and remediation

A Denied decision records that access should be removed. It doesn’t remove the access on its own. When the review is complete, the owner selects the denied grants and runs remediation to actually deprovision them. This keeps the review separate from remediation, so you can complete and audit a review before any access is touched.

Reports

From the Reports tab, Generate report produces an audit export; its menu chooses the format. XLSX workbooks include a summary, resources in scope, the full per-grant decision matrix, and revocations. CSV exports contain the per-grant decision matrix for importing into analysis and compliance tools.

Access management overview

Roles, access policies, and provisioning.

Access profiles

Control who can request which roles.