Recertification
Access recertification is the formal review process where designated leaders periodically attest that users hold only the group memberships and roles they legitimately need. The cidaas Review Center provides a dedicated, audit-ready interface to manage campaigns, submit reviews, and export compliance evidence.
Access Governance cidaas 4.x Audit Evidence REST API Coming soon
Recertification API — Coming soon
Public Recertification REST API documentation is not published yet. Use the Review Center portal for campaign management until the API reference is available.
How it works
In Progress. Reviewers receive email assignment notifications.Roles and permissions
| Role | Responsibilities | Setup in Trustdesk |
|---|---|---|
| Campaign Manager | Create, edit, monitor, close campaigns, and export reports | Group CIDAAS_RECERTIFICATION with role CAMPAIGN_MANAGER |
| Campaign Viewer | Read-only access to campaign progress and audit reports | Group CIDAAS_RECERTIFICATION with role CAMPAIGN_VIEWER |
| Reviewer | Attest user access for assigned groups within active windows | No group role required; assigned per campaign |
| Administrator | Configure the client application and provision group roles | Trustdesk tenant administrator |
Reviewer strategies
When creating a campaign, the Campaign Manager selects how reviewer decisions are collected:
- Parallel One: At least one assigned reviewer must complete each user. Ideal when any qualified team lead can validate access.
- Parallel All: Every assigned reviewer must submit a decision before the user's status is finalized.
Conflict resolution (Parallel All)
When multiple reviewers evaluate the same user in a group, individual reviews are combined into a single final decision:
- Keep: When all reviewers agree to keep a role, that role is approved and retained for the user. If all assigned roles are kept across the board, the final decision is Keep.
- Revoke: When all reviewers agree to revoke access, the user's access is removed.
- Change access (partial removal): Occurs when a group has multiple roles and only some roles are marked for removal while others are kept. If any reviewer chooses to modify roles (or if reviewers agree on keeping some roles but revoking others), the final decision is recorded as Change access.
- Conflict precedence (Keep vs. Revoke): If reviewers disagree on a role or group (for example, one reviewer votes Keep and another votes Revoke), Keep takes precedence to prevent accidental access revocation.
Administrator setup
Administrators perform this one-time configuration in Trustdesk (/trust-desk):
1. Create the Review Center client app
- Go to Trustdesk → Apps (
/trust-desk/apps) and create a new client application. - Configure the following core settings:
| Setting | Value |
|---|---|
| Grant types | authorization_code |
| Response types | code |
| Allowed scopes | openid, profile, groups, offline_access, cidaas:campaign_read, cidaas:campaign_write, cidaas:campaign_delete, cidaas:campaign_review |
| Redirect URL | https://<your-tenant>/review-center/<app-name>/overview |
| SSO | Enabled |
| Template group | Select your preferred notification branding for campaign emails |
2. Grant user access
- Open Trustdesk → User management → Groups and roles.
- Add the user to group
CIDAAS_RECERTIFICATION. - Assign role
CAMPAIGN_MANAGERorCAMPAIGN_VIEWER.
Campaign Manager guide
Campaign Managers access the portal at:
https://<your-tenant>/review-center/<app-name>/overview
Create a campaign
Select Create New Campaign in the header to open the 4-step wizard:
- Campaign details: Enter a unique name (3–128 characters), choose the review window (start time must be at least 15 minutes in the future), and select the reviewer strategy (Parallel One or Parallel All).
- Assign groups: Search and select one or more groups requiring access review. Groups without members are omitted automatically.
- Assign reviewers: Group admins are assigned as default reviewers. Click Manage to add external reviewers or replace default assignments. Every group must have at least one reviewer.
- Summary and launch: Verify the configuration and click Launch Campaign.
Campaign lifecycle and editing
| Status | Editable fields | Actions available |
|---|---|---|
| Planned | Name, dates, strategy, groups, reviewers | View details, Edit, Delete campaign |
| In Progress | Name, end date (future only), reviewers | View details, Edit, Export report, Close early |
| Completed | None (read-only audit state) | View details, Export report |
A campaign automatically moves to Completed when its end date is reached, when closed manually, or as soon as all assigned users have been reviewed by reviewers—even before the scheduled end date.
To close an in-progress campaign early, select Close Campaign from the card overflow menu (⋯) and enter a mandatory reason.
Reviewer guide
When assigned as a reviewer, the Review button appears on campaign cards during the active review window alongside Edit (if you also hold Campaign Manager permissions).
Review workspace
Clicking Review opens the campaign review workspace:
- Campaign header: Displays the campaign name, reviewer strategy badge (Parallel One or Parallel All), review window dates, and a countdown timer showing the remaining days.
- Review progress strip: Tracks real-time completion across five key indicators:
- Finalized: Users whose review decisions have been finalized.
- Submitted by you: Reviews you have saved and submitted.
- Pending for you: Users awaiting your review.
- Waiting for other reviewers: Reviews you submitted that await other reviewers in Parallel All strategy.
- Overall pending: Total users across the campaign still awaiting final decision.
- Review tabs:
- Pending for Review: Lists users and groups awaiting your attestation, with search by user, group, or role.
- Completed reviews: Displays all submitted decisions with reviewer comments and decision tags.
Review actions and decisions
Reviewers evaluate users individually or using batch actions:
| Action | Decision | Description |
|---|---|---|
| Keep all | Keep | User retains group membership and all active roles. |
| Revoke all | Revoke | Removes the user from all groups in the review. |
| Remove from group | Revoke | Removes the user from that specific group. |
| Remove individual role | Change access | Removes that specific role; remaining roles stay intact. |
| Remove all roles | Change access | Removes all roles while retaining group membership (if permitted). |
If a group is configured in Roles Required mode (roles_required), removing all roles while keeping membership is not permitted. You must retain at least one role or use Remove from group to remove the user entirely.
Batch submission rules
- Batch limit: You can submit up to 100 users per save. If reviewing larger groups, submit in batches.
- Bulk checkboxes: Select multiple users to apply Keep or Revoke across the selection.
- Reset: Clears unsaved on-screen changes without sending data to the server.
- Audit confirmation: Once saved, decisions are written to the immutable audit trail and cannot be undone from the portal.
Reports and audit export
Campaign Managers and Campaign Viewers can open the Campaign Report via Export on any In Progress or Completed campaign.
The report provides a high-level summary header with campaign metrics, filter options, and a comprehensive user-by-user audit list showing each group, role decision, reviewer identity, and timestamp.
Export formats
| Format | Recommended for | Details |
|---|---|---|
| CSV | Spreadsheets and external audit workpapers | Tabular data with reviewer names, timestamps, and notes. |
| JSON | SIEM ingestion, compliance automation, archives | Nested payload including previous vs. updated role state. |
CSV and JSON downloads retrieve the complete campaign dataset from the server. On-screen search filters only affect the browser display and do not truncate the export.
Frequently asked questions
For common troubleshooting steps, reviewer strategy conflict resolution rules, and audit report FAQs, see the dedicated Access Recertification FAQs.
Contact the team on our support page or reach out to [email protected].