Recertification
This guide helps Campaign Managers, Campaign Viewers, and Reviewers use the Recertification Review Center — what the portal does, how access works, and how to complete each task.
Find your task
- Campaign Manager — Create, manage, close, and report on campaigns.
- Campaign Viewer — View campaigns and export audit reports.
- Reviewer — Review assigned users and submit access decisions.
- Administrator — Configure access and help users with permissions or login issues.
Audience
| Role | What you will do in the Review Center |
|---|---|
| Campaign Manager | Create and manage campaigns, assign reviewers, monitor progress, close campaigns, export reports |
| Campaign Viewer | Monitor campaigns, view details, and export audit reports (read-only) |
| Reviewer | Review user access for assigned groups and submit Keep / Revoke / Change access decisions |
Why recertification matters
Organizations grant access through groups and roles. Over time, people change roles, leave the company, or no longer need certain permissions. Access recertification is the structured process of asking the right people to confirm — on a regular schedule — that each user should still have the access they currently hold.
The cidaas Recertification portal helps you:
- Reduce risk — Identify and remove stale or excessive access before it becomes a security issue.
- Support compliance processes — Produce timestamped review records and exportable reports that your audit or GRC teams can use as evidence.
- Distribute accountability — Assign group-level reviewers who know the business context, instead of relying on a central IT team alone.
- Track progress in real time — See how many users have been reviewed, which groups are complete, and what decisions were made.
Using this portal supports access governance. It does not by itself certify that your organization meets any specific regulatory framework.
How it works — at a glance
- A Campaign Manager defines which groups to review, who will review them, and the review window.
- When the campaign reaches its start date, it moves to In Progress and reviewers can begin.
- Reviewers examine each user’s group memberships and roles, then choose Keep, Revoke, or Change access.
- When the campaign ends (or is closed early), Campaign Managers and Campaign Viewers can open the Campaign Report and export CSV or JSON for compliance records.
Before you log in — what you need
You do not configure the Review Center inside Trust Desk. Trust Desk (admin UI) is where administrators assign users to groups and roles. The Recertification Review Center is a separate application at /review-center/<app-name>/.
Administrator setup (Trust Desk)
To grant Campaign Manager or Campaign Viewer access:
- Open Trust Desk → User management.
- Open the user profile → Groups and roles.
- Add group membership (or Edit group roles) for group CIDAAS_RECERTIFICATION.
- Assign role CAMPAIGN_MANAGER or CAMPAIGN_VIEWER for that group.
- Save. The user can then open the Review Center URL.
Reviewers do not need these roles — they only need to be assigned on a campaign (see below).
1. Portal URL
Your administrator will provide a link in this format:
https://<your-tenant>/review-center/<app-name>/overview
Bookmark this URL. After signing in, you land on the Campaign Management overview page.
2. Valid user account
You must have an active cidaas account with permission to open the Review Center application. If you cannot sign in, or you see Access restricted after login, contact your administrator.
3. Access requirements (Campaign Managers and Campaign Viewers)
Access is controlled by membership in the recertification group with the correct role:
| Portal role | Group | Role |
|---|---|---|
| Campaign Manager | CIDAAS_RECERTIFICATION | CAMPAIGN_MANAGER |
| Campaign Viewer | CIDAAS_RECERTIFICATION | CAMPAIGN_VIEWER |
- Campaign Manager — full campaign management (create, edit, delete planned campaigns, close in-progress campaigns, report, export)
- Campaign Viewer — read-only access to campaigns and reports (view, export)
4. Reviewer assignment (Reviewers)
If you are a Reviewer, you do not need the Campaign Manager or Campaign Viewer role. A Campaign Manager (or administrator) assigns your account directly as a reviewer on one or more groups in a campaign. You only see campaigns where you are assigned.
Signing in
- Open the Review Center URL provided by your administrator.
- Authenticate with your organization’s identity provider (SSO, username/password, and MFA as configured for your tenant).
- You arrive at the Campaign Management overview.
From the header User menu you can:
- Open Profile (when available for the app)
- Sign Out when you are finished
Understanding your role
What you see and what you can do depend on your role.
| Capability | Campaign Manager | Campaign Viewer | Reviewer |
|---|---|---|---|
| View tenant campaigns | Yes | Yes | Assigned campaigns only |
| Create campaigns | Yes | No | No |
| Edit campaigns | Yes | No | No |
| Delete Planned campaigns | Yes | No | No |
| Close In Progress campaigns | Yes | No | No |
| Submit reviews | Only if also assigned as a reviewer | Only if also assigned as a reviewer | Yes, when assigned |
| View / export campaign report | Yes | Yes | No |
Important: Campaign Managers and Campaign Viewers can use the Review workspace only when they are personally assigned as a reviewer on that campaign and the campaign is inside its active review window.
Campaign overview
The overview page is your home screen after login.
Page header
The banner at the top explains the purpose of recertification:
- Title: Campaign Management
- Description: Periodically review Group memberships and prove compliance. Campaigns define which Groups are reviewed, who reviews them, and the review timeframe.
Campaign Managers also see Create New Campaign.
Search, filter, and sort
Use the toolbar to find campaigns. The search box placeholder is Type to search or select a field.
- Type text and press Enter to search by Campaign Name.
- Or select a field such as Status, then choose a value.
| Control | Options |
|---|---|
| Search | Campaign name (contains), or select a field |
| Status | All · Planned · In Progress · Completed |
| Sort | Updated date (newest) · End date (soonest) |
The result count shows how many campaigns match (for example, 660 Campaigns). Long lists are paginated (for example, 1–20 of 660 items).
Campaign cards
Each campaign appears as a card showing:
| Element | Description |
|---|---|
| Campaign name | Name given when the campaign was created |
| Status badge | Planned · In Progress · Completed |
| Strategy badge | Parallel One or Parallel All (see Reviewer strategies) |
| Time remaining | Time remaining indicator (for example, Ends in 258 days), or Due today |
| Review window | Start and end date/time |
| User count | Total users included |
| Group count | Number of groups under review |
| Progress | Review status percentage and X / Y users reviewed |
| Last updated | When the campaign was last modified |
Quick actions on each card:
- Edit — Campaign Managers only; for Planned and In Progress campaigns
- Review — Assigned reviewers only; during the active review window
Overflow menu (⋯):
| Action | Who can use it | When available |
|---|---|---|
| View Details | Everyone with access to the campaign | Always |
| Export | Campaign Manager, Campaign Viewer | In Progress or Completed (not Planned) |
| Close Campaign | Campaign Manager | In Progress only |
| Delete Campaign | Campaign Manager | Planned only |
Campaign details dialog
Select View Details from the overflow menu to open the details dialog (title Details: plus the campaign name) — a read-only summary:
- Campaign status, start/end dates, time remaining ("Ends in"), strategy, created by, created time, last updated, groups, and overall progress
- Table of groups with per-group status (Pending, In progress, Completed), progress, and reviewers
- Footer actions based on permissions (for example Export Report, Close; Edit / Review when available)
Campaign lifecycle
| Status | Meaning | Typical actions |
|---|---|---|
| Planned | Created; review window has not started | Campaign Manager can edit fully or delete |
| In Progress | Review window is open | Reviewers submit decisions; Campaign Manager can edit limited fields or close early |
| Completed | Review window ended, or the campaign was closed early | View report and export; no further reviews |
Closing an in-progress campaign early sets the campaign to Completed and stops further reviews. Submitted decisions remain in the audit trail.
Reviewer strategies
When a campaign is created, the Campaign Manager chooses how multiple reviewers participate.
Parallel One
At least one assigned reviewer must review each user’s access. Not every reviewer needs to complete every user.
- Best when any qualified reviewer can attest to access
- Faster when groups have several reviewers
- The report lists every review submitted
Parallel All
Every assigned reviewer must submit their review before a user’s access decision is finalized.
- Best when multiple independent reviews are required
- Progress distinguishes submitted by you vs finalized
- The report lists the final decision; expand a row to see each reviewer’s decision
Final decision rules (Parallel All) — as shown in the Campaign Report:
| Reviewer decisions | Final decision |
|---|---|
| All Keep | Keep |
| All Revoke | Revoke |
| Any Change access | Change access |
| Mix of Keep and Revoke (no Change access) | Keep (Keep takes precedence over Revoke) |
Creating a campaign (Campaign Managers)
Campaign Managers use a guided four-step wizard to define the review period, select groups, assign reviewers, and launch the campaign. Step titles in the UI:
- Create New Recertification Campaign (campaign details)
- Assign Groups: plus the campaign name
- Assign Reviewers: plus the campaign name
- Summary: plus the campaign name
Step 1 — Campaign details
| Field | Guidance |
|---|---|
| Campaign Name | Required; 3–128 characters; must be unique |
| From | Start date and time; must be at least 15 minutes from now |
| To | End date and time; must be after the start |
| Reviewer Strategy | Parallel One (default) or Parallel All |
Click Next when all fields are valid. Use Cancel to leave without creating a campaign.
Step 2 — Assign groups
- Search with Search by group name
- Select one or more groups (selected groups appear under Selected groups)
- At least one group is required
- Groups with zero users are not shown
- User counts appear on each group (large groups may show as
10+ Users)
Click Next when at least one group is selected. Use Back to return to campaign details.
Step 3 — Assign reviewers
Every selected group must have at least one reviewer.
The page explains that group admins are assigned as reviewers by default when available, and that you can replace them or add other users with the edit icon in Manage.
| Column | Description |
|---|---|
| Group Name | Group under review (with user count) |
| Assigned Reviewers | Default reviewers (group admins) and/or external reviewers already chosen |
| Manage | Edit external reviewers, or remove the group / clear reviewers |
Tips:
- If there are no default reviewers, the table shows: No default reviewers. Select at least one external reviewer.
- Use Manage (edit) to open Assign reviewers and search by name or email
- Use the table search to filter by group or reviewer
- You can remove a group from the campaign or clear reviewers and assign again
Click Next when every group has reviewers.
Step 4 — Summary
Review settings before launch:
- Campaign name and review window
- Strategy
- Selected groups and assigned reviewers
Click Launch Campaign to create the campaign. You return to the overview with a success confirmation.
Editing a campaign (Campaign Managers)
Open Edit from a campaign card (or details, when available).
| Campaign status | What you can change |
|---|---|
| Planned | Name, dates, strategy, groups (add/remove), reviewers |
| In Progress | Name, end date, and external reviewers on existing groups only |
For in-progress campaigns, the portal shows a Limited editing notice:
This campaign is in progress. You can update the campaign name, end date, and external reviewers. Groups and review strategy cannot be changed.
Click Save Changes to apply updates. If nothing changed, the portal shows No changes to save. and does not update the server. The end date must be in the future.
Closing or deleting a campaign (Campaign Managers)
Close an in-progress campaign early
- Open the overflow menu on an In Progress campaign.
- Select Close Campaign.
- Read the warning (Close This Campaign Early?): closing stops further reviews; decisions already submitted remain in the audit trail.
- Enter a Reason for closing (required).
- Confirm Close Campaign.
The campaign becomes Completed. Pending reviews can no longer be submitted.
Delete a planned campaign
- Open the overflow menu on a Planned campaign.
- Select Delete Campaign.
- Confirm Delete This Planned Campaign? The portal warns that the action cannot be undone and permanently removes the campaign from the system.
Only Planned campaigns can be deleted. In Progress and Completed campaigns cannot be deleted from the portal.
Reviewing user access (Reviewers)
When you are assigned as a reviewer and the campaign is In Progress within its review window, Review appears on the campaign card.
Opening the review workspace
The review workspace shows:
- Campaign name, strategy, and review window
- Time remaining ("Ends in")
- Progress and statistics (labels differ for Parallel One vs Parallel All)
- Expandable Legend explaining decision types and progress colors
Pending and completed tabs
| Tab | Contents |
|---|---|
| Pending for Review | Users still awaiting your decision |
| Completed reviews | Users you have already submitted reviews for |
Use the search box (User, group, or role) to filter. Scroll to load more users when the list is long (Showing X of Y … — scroll for more).
Understanding the review table
Each row represents a user’s membership in a group:
| Column | Description |
|---|---|
| User | Person whose access is under review |
| Group | Group membership being reviewed |
| Roles | Roles in that group — keep or remove individual roles |
| Comment | Optional note |
| Decision | Current decision (Pending, Keep, Revoke, and related states) |
Users in multiple groups may span several rows. Use Show more groups to expand.
If a user has membership but no roles, the table can show Membership only — no roles assigned in this group.
Making decisions
You can review users individually or in bulk. Changes stay local until you click Save.
Per user / per group actions:
| Action | Effect (as a review decision) |
|---|---|
| Keep all | Keep all group memberships and roles for the user |
| Revoke all | Revoke all memberships and roles for the user |
| Keep (group) | Keep all roles in that group |
| Remove all roles | Remove every role in that group |
| Remove (individual role) | Remove one role; other roles stay |
| Remove from group | Remove the user from the group entirely |
Bulk actions (footer):
- Select one or more users with the checkboxes.
- Use Keep or Revoke for the selection.
- Click Save to submit (up to 100 users per save).
- Click Reset to clear unsaved changes (the server is not called; a toast confirms that unsaved changes were cleared).
Before saving, a confirmation dialog summarizes what will change. After a successful save, those reviews move to Completed reviews.
100-user limit (confirmed in the application):
- You can review and submit up to 100 users per save.
- If you reach the limit, save before selecting or reviewing more users.
- Selecting “all” may automatically limit selection to the first 100 pending users.
Groups that require at least one role
Some groups use a Roles Required mode (roles_required / allowedRolesRequired). While the user remains a member of those groups:
- You cannot remove every role without also removing the user from the group
- The portal shows: This group requires at least one role.
Retain at least one role, or use Remove from group to revoke membership entirely.
When reviews are blocked
If the campaign has not started, has ended, or is not in progress, a banner appears and submit actions are disabled:
| Situation | Message (summary) |
|---|---|
| Before start | This campaign has not started yet. Reviews can be submitted after the campaign start time. |
| After end | This campaign has ended. Reviews can no longer be submitted. |
| Not in progress | This campaign is not in progress. Reviews cannot be submitted. |
Review button vs workspace:
- Review on the card is intended for assigned reviewers during the active review window.
- Opening the review route outside that window may still show the workspace shell with the blocked banner and disabled submit actions.
After you save
- Submitted reviews move to Completed reviews
- A success toast confirms how many decisions were saved
- In Parallel All campaigns, other reviewers may still need to submit before access is finalized
- Submitted reviews are part of the audit trail and cannot be undone from the portal. Contact your Campaign Manager if a correction is needed before the campaign completes.
Campaign report and export (Campaign Managers and Campaign Viewers)
Open a report from Export on a campaign card, or Export Report in the details dialog. Reports are available for In Progress and Completed campaigns (not Planned).
Report header
The report page shows:
- Campaign name, status, and strategy
- Review window
- Strategy explanation:
- Parallel One: At least one reviewer must submit their review. Every review is listed.
- Parallel All: All reviewers must submit. Rows show the final decision — expand a row for individual reviews. If reviewers disagree, Keep takes precedence over Revoke.
- Summary statistics:
- Parallel One: Total Users, Total Users Reviewed, Keep, Access Modified
- Parallel All: Total Users, Finalized, Pending for other reviewers (when shown), Keep, Access Modified
- Export CSV and Export JSON
Filters
Narrow the on-screen table:
| Filter | Description |
|---|---|
| Group | One or more groups |
| Reviewer | One or more reviewers |
| Decision | Keep · Revoke · Change access |
Select values to narrow the table. Use Clear Filters to reset. (There is no separate Apply filters button on the report page.)
Report table
| Column | Description |
|---|---|
| User | Reviewed person |
| Group | Group context |
| Roles | Roles (shown as chips) |
| Reviewer | Who submitted the review |
| Reviewed at | Timestamp |
| Comment | Reviewer comment, if any |
| Decision | Keep · Revoke · Change access |
Click column headers to sort. Expand a row when multiple reviewers submitted decisions (common with Parallel All).
Exporting for audit evidence
| Format | Best for |
|---|---|
| CSV | Spreadsheets and audit workpapers |
| JSON | System integration and archival |
Exports download immediately. The export API requests the campaign export by format only — on-screen filters do not limit the export file. The download contains the full campaign report from the server.
After export, the file downloads in the browser and a success notice confirms the download (for example, Report exported successfully).
Decision reference
| Decision | Meaning in the report / review |
|---|---|
| Keep | User retains current group membership and roles for that context |
| Revoke | Review decision to revoke group membership / access in that group |
| Change access | User stays in the group but one or more roles were removed or modified (internally also called REDUCE / UPDATE) |
Review actions record review decisions for the campaign audit trail. Use your organization’s process (and Campaign Manager) to confirm how and when access changes are applied in your environment after decisions are submitted or the campaign completes.
Frequently asked questions
I cannot see any campaigns after login
- Reviewers: You only see campaigns where you are assigned. Ask your Campaign Manager to confirm your account is listed as a reviewer.
- Campaign Managers / Campaign Viewers: Confirm you signed in with the correct recertification group and role. Contact your administrator if the list is still empty.
I see "Access restricted"
Your account does not have the required role or assignment for that action. Contact your administrator to grant CAMPAIGN_MANAGER, CAMPAIGN_VIEWER, or reviewer assignment on the relevant campaign.
Why is the Review button missing?
All of the following must be true:
- You are assigned as a reviewer on the campaign
- Campaign status is In Progress
- Current date/time is within the campaign review window (From → To)
Can I review users before the campaign start date?
Submit actions are disabled until the campaign start date and time. The review workspace may open with a banner: reviews can be submitted after the start time.
How many users can I save at once?
Up to 100 users per save. If you reach the limit, save your current batch before selecting or reviewing more users.
What does Reset do?
Reset clears unsaved changes in the review workspace. It does not call the server and does not change already submitted reviews.
Does exporting respect my on-screen filters?
No. CSV and JSON exports contain the complete campaign report. Use filters only for on-screen analysis.
What happens if reviewers disagree (Parallel All)?
- Any Change access decision makes the final decision Change access
- Otherwise, if decisions mix Keep and Revoke, the final decision is Keep
- Expand the user row in the report to see each reviewer’s individual decision
Can I undo a submitted review?
Submitted reviews are part of the audit trail and cannot be undone from the portal. Contact your Campaign Manager if a correction is needed before the campaign completes.
What happens when a campaign is closed with pending reviews?
Closing stops further reviews. Already submitted decisions remain. The campaign status becomes Completed.
Glossary
| Term | Definition |
|---|---|
| Campaign | A time-bound access review covering one or more groups |
| Review window | The period between the campaign start (From) and end (To) dates |
| Group | A cidaas user group whose memberships are under review |
| Reviewer | A person assigned to validate access for users in a specific group |
| Campaign Manager | Role that can create and manage campaigns (CAMPAIGN_MANAGER) |
| Campaign Viewer | Role with read-only campaign and report access (CAMPAIGN_VIEWER) |
| Parallel One | Strategy where at least one reviewer must complete each user |
| Parallel All | Strategy where every assigned reviewer must complete each user |
| Campaign report | Read-only record of review decisions, exportable for audit evidence |
| Review Center | The cidaas portal hosting the Recertification application |
Getting help
| Issue | Contact |
|---|---|
| Cannot sign in or missing CAMPAIGN_* role | Your IT administrator (Trust Desk → User management → Groups and roles) |
| Missing reviewer assignment | Your Campaign Manager |
| Incorrect access after a review decision | Your Campaign Manager (before the campaign completes) |
| Compliance / audit questions | Your organization’s audit or GRC team |