Skip to content
English

Daily review and periodic access review

Once the evidence is there, someone has to look at it regularly. This page covers four kinds of follow-up work: the daily sign-off on security events, dispositions on alerts, the periodic access review, and the alert that watches for new source addresses. It ends with the self-service page for ordinary users, because that is another projection of the same records.

The policy key “daily review sign-off” ships off. If an in-force policy group requires it on, the drawer shows that requirement. Once it is on, anyone with audit view permission sees a “daily security review” card on the dashboard showing three counts for the day: failed logins, unreviewed alerts, and high-risk operations.

After checking the counts, add a note if you want and press “Sign off today’s review”. There is at most one per day, and a card already signed off shows who signed it, when, and the note. When yesterday went unsigned, a reminder goes out over the notification channels the next morning.

How the counts are defined: failed logins cover both failure and refusal states of authentication events, leaving out routine credential expiry, which still stays in the records one by one. High-risk operations are a list: deletion of any resource, writes to security policy, log forwarding, and exports, and the creation and updating of accounts.

The dashboard of a non-auditor role does not show this card.

The dashboard daily-review card links to the Daily review tab in Operation logs, where past signoffs, reviewers, times, notes, and count snapshots can be inspected.

On the alert records tab of the Alerts page, the list can show only the unreviewed ones. Press Review, choose a disposition (false positive or harmless, or escalate), and add an explanation if you want. A disposition can be redone, which is how a misjudgment gets corrected. The reviewer, time, classification, and note all stay on that alert.

Up to 50 alerts can be reviewed in a batch with one shared reason and individual results. Requery after a partial result. A reviewer’s own alerts are excluded. Pending break-glass reviews also support batch confirmation, while violations are decided individually.

The Access Reviews page is open to the administrator and auditor roles, and signing off is for administrators. The page shows how long it has been since the last review, how many days the suggested cycle is, and whether it is overdue, with the cycle value supplied by the server.

Pressing “Start an access review” explains that the action snapshots the complete access matrix as it stands as immutable evidence, and records a sign-off with the reviewer, time, and conclusion. The conclusion field holds the outcome of this review, for example that everything was examined and nothing was out of order, or a list of adjustments.

The history lists every review with its reviewer, time, number of authorizations, and conclusion, and “View snapshot” shows the authorization matrix as it was: authorization identifier, subject, object, and scope. When a snapshot is damaged the system returns a clear error rather than handing over empty content that looks fine.

The first time an account opens a protocol connection from a given address, the system produces a medium-severity alert. The baseline is the account and address pair, so connecting again from the same address does not alert again. The baseline transition and the alert are written in one transaction, and the notification is sent after the transaction commits.

Alerts of this kind hang on no rule, so disabling a rule does not make them disappear. The address on the alert row is a link that opens the investigation workbench pivoted on that address, with the time window set to the day of the alert and every category selected.

A web login from a new address is handled differently: it leaves an audit record and enters the baseline, without producing an alert or a push. This baseline falls outside the purge scope of every retention policy.

Ordinary users have a self-service “My connections” page showing what they connected to: asset name, protocol, connection time, duration, and status. A connection in progress can be terminated by the user, with a second confirmation, and the record notes that the user ended it themselves.

The page is a narrow projection built from a list of allowed fields, without commands, recordings, credentials, source addresses, or target host addresses, and with no entrance to command views or playback. Termination recognizes the owner alone, and someone else’s connection reads as not found.

  • A daily review sign-off leaves a record and keeps the count snapshot and the note as they were.
  • An alert disposition leaves a record with its classification.
  • An access review sign-off leaves a record, and the snapshot itself is immutable.
  • A new source address alert is bound to that session, user, and asset, and the address is carried by the session it belongs to.
  • A user terminating their own connection leaves a record with themselves as the operator.