Skip to main content
Version: 4.0.4

Recertification

Access recertification is the formal review process where designated leaders periodically attest that users hold only the group memberships and roles they legitimately need. The cidaas Review Center provides a dedicated, audit-ready interface to manage campaigns, submit reviews, and export compliance evidence.

Access Governance cidaas 4.x Audit Evidence REST API Coming soon

info

Recertification API — Coming soon​

Public Recertification REST API documentation is not published yet. Use the Review Center portal for campaign management until the API reference is available.


How it works​

1
Configure and Launch
Campaign Manager defines scope, target groups, reviewer assignments, and time window.
2
Review Window Opens
Campaign transitions to In Progress. Reviewers receive email assignment notifications.
3
Access Attestation
Reviewers evaluate users and submit decisions (Keep, Revoke, or Change roles).
4
Close and Export
Campaign completes. Auditors generate tamper-evident CSV and JSON audit reports.

Roles and permissions​

RoleResponsibilitiesSetup in Trustdesk
Campaign ManagerCreate, edit, monitor, close campaigns, and export reportsGroup CIDAAS_RECERTIFICATION with role CAMPAIGN_MANAGER
Campaign ViewerRead-only access to campaign progress and audit reportsGroup CIDAAS_RECERTIFICATION with role CAMPAIGN_VIEWER
ReviewerAttest user access for assigned groups within active windowsNo group role required; assigned per campaign
AdministratorConfigure the client application and provision group rolesTrustdesk tenant administrator

Reviewer strategies​

When creating a campaign, the Campaign Manager selects how reviewer decisions are collected:

  • Parallel One: At least one assigned reviewer must complete each user. Ideal when any qualified team lead can validate access.
  • Parallel All: Every assigned reviewer must submit a decision before the user's status is finalized.

Conflict resolution (Parallel All)​

When multiple reviewers evaluate the same user in a group, individual reviews are combined into a single final decision:

  • Keep: When all reviewers agree to keep a role, that role is approved and retained for the user. If all assigned roles are kept across the board, the final decision is Keep.
  • Revoke: When all reviewers agree to revoke access, the user's access is removed.
  • Change access (partial removal): Occurs when a group has multiple roles and only some roles are marked for removal while others are kept. If any reviewer chooses to modify roles (or if reviewers agree on keeping some roles but revoking others), the final decision is recorded as Change access.
  • Conflict precedence (Keep vs. Revoke): If reviewers disagree on a role or group (for example, one reviewer votes Keep and another votes Revoke), Keep takes precedence to prevent accidental access revocation.

Administrator setup​

Administrators perform this one-time configuration in Trustdesk (/trust-desk):

1. Create the Review Center client app​

  1. Go to Trustdesk → Apps (/trust-desk/apps) and create a new client application.
  2. Configure the following core settings:
SettingValue
Grant typesauthorization_code
Response typescode
Allowed scopesopenid, profile, groups, offline_access, cidaas:campaign_read, cidaas:campaign_write, cidaas:campaign_delete, cidaas:campaign_review
Redirect URLhttps://<your-tenant>/review-center/<app-name>/overview
SSOEnabled
Template groupSelect your preferred notification branding for campaign emails

2. Grant user access​

  1. Open Trustdesk → User management → Groups and roles.
  2. Add the user to group CIDAAS_RECERTIFICATION.
  3. Assign role CAMPAIGN_MANAGER or CAMPAIGN_VIEWER.

Campaign Manager guide​

Campaign Managers access the portal at:

https://<your-tenant>/review-center/<app-name>/overview

Create a campaign​

Select Create New Campaign in the header to open the 4-step wizard:

  1. Campaign details: Enter a unique name (3–128 characters), choose the review window (start time must be at least 15 minutes in the future), and select the reviewer strategy (Parallel One or Parallel All).
  2. Assign groups: Search and select one or more groups requiring access review. Groups without members are omitted automatically.
  3. Assign reviewers: Group admins are assigned as default reviewers. Click Manage to add external reviewers or replace default assignments. Every group must have at least one reviewer.
  4. Summary and launch: Verify the configuration and click Launch Campaign.

Campaign lifecycle and editing​

StatusEditable fieldsActions available
PlannedName, dates, strategy, groups, reviewersView details, Edit, Delete campaign
In ProgressName, end date (future only), reviewersView details, Edit, Export report, Close early
CompletedNone (read-only audit state)View details, Export report

A campaign automatically moves to Completed when its end date is reached, when closed manually, or as soon as all assigned users have been reviewed by reviewers—even before the scheduled end date.

To close an in-progress campaign early, select Close Campaign from the card overflow menu (⋯) and enter a mandatory reason.


Reviewer guide​

When assigned as a reviewer, the Review button appears on campaign cards during the active review window alongside Edit (if you also hold Campaign Manager permissions).

Review workspace​

Clicking Review opens the campaign review workspace:

  • Campaign header: Displays the campaign name, reviewer strategy badge (Parallel One or Parallel All), review window dates, and a countdown timer showing the remaining days.
  • Review progress strip: Tracks real-time completion across five key indicators:
    • Finalized: Users whose review decisions have been finalized.
    • Submitted by you: Reviews you have saved and submitted.
    • Pending for you: Users awaiting your review.
    • Waiting for other reviewers: Reviews you submitted that await other reviewers in Parallel All strategy.
    • Overall pending: Total users across the campaign still awaiting final decision.
  • Review tabs:
    • Pending for Review: Lists users and groups awaiting your attestation, with search by user, group, or role.
    • Completed reviews: Displays all submitted decisions with reviewer comments and decision tags.

Review actions and decisions​

Reviewers evaluate users individually or using batch actions:

ActionDecisionDescription
Keep allKeepUser retains group membership and all active roles.
Revoke allRevokeRemoves the user from all groups in the review.
Remove from groupRevokeRemoves the user from that specific group.
Remove individual roleChange accessRemoves that specific role; remaining roles stay intact.
Remove all rolesChange accessRemoves all roles while retaining group membership (if permitted).
Roles Required mode

If a group is configured in Roles Required mode (roles_required), removing all roles while keeping membership is not permitted. You must retain at least one role or use Remove from group to remove the user entirely.

Batch submission rules​

  • Batch limit: You can submit up to 100 users per save. If reviewing larger groups, submit in batches.
  • Bulk checkboxes: Select multiple users to apply Keep or Revoke across the selection.
  • Reset: Clears unsaved on-screen changes without sending data to the server.
  • Audit confirmation: Once saved, decisions are written to the immutable audit trail and cannot be undone from the portal.


Reports and audit export​

Campaign Managers and Campaign Viewers can open the Campaign Report via Export on any In Progress or Completed campaign.

The report provides a high-level summary header with campaign metrics, filter options, and a comprehensive user-by-user audit list showing each group, role decision, reviewer identity, and timestamp.

Export formats​

FormatRecommended forDetails
CSVSpreadsheets and external audit workpapersTabular data with reviewer names, timestamps, and notes.
JSONSIEM ingestion, compliance automation, archivesNested payload including previous vs. updated role state.
Export scope

CSV and JSON downloads retrieve the complete campaign dataset from the server. On-screen search filters only affect the browser display and do not truncate the export.

Frequently asked questions​

For common troubleshooting steps, reviewer strategy conflict resolution rules, and audit report FAQs, see the dedicated Access Recertification FAQs.


Need support?

Contact the team on our support page or reach out to [email protected].