Vaultic
Web App

Access reviews

Periodic, evidence-producing reviews of every member, access grant, and service token in a workspace.

SOC 2 (CC6.2, CC6.3), ISO 27001 (A.5.18), and most customer security questionnaires require a documented, signed-off confirmation that the people and machines with access to a workspace still need it. Access review campaigns run that process inside Vaultic and produce the evidence as a by-product, instead of a spreadsheet exported once and never looked at again.

Team plan. See Team management for roles/access grants and Access, team & tokens for the pages a campaign reviews.

Campaigns

Admin-only. A campaign is scoped to the whole workspace, or narrowed to specific projects at creation. Creating one enumerates — at that moment, frozen — every workspace member, every access grant in scope, and every non-revoked service token in scope, each becoming a reviewable item.

A new campaign starts as DRAFT: reviewed items can be re-assigned before anyone is notified. Starting it notifies every assigned reviewer (in-app notification + email) and moves it to ACTIVE.

Each item shows usage context alongside what it grants — last login for a member, who granted it and when for an access grant, last-used and expiry for a token — so a reviewer isn't deciding blind. An item with no recorded usage is flagged, since that's the one worth actually looking at.

Deciding an item

The assigned reviewer (or any workspace owner) can Certify or Revoke each item, with an optional note:

  • Certify records the decision. No side effect — the access is unchanged.
  • Revoke immediately removes the access: the grant is deleted, the token is revoked, or the member is removed from the workspace. This runs through the same code paths — and the same protections — as removing access directly, including that a workspace can never be left without an owner. If that protection stops the revocation from executing, the decision is still recorded with the failure attached, rather than silently succeeding or silently failing.

A campaign completes automatically once every item has a decision, or an admin can force-complete it early — anything still pending stays pending in the record rather than being silently certified.

Evidence export

A completed campaign exports as CSV or JSON: every item's frozen snapshot, decision, reviewer, and execution result. The snapshot is what's exported even if the underlying grant or token has since been deleted — an auditor asking "what did this reviewer certify" gets a truthful answer, not a broken reference.

Recurrence

Set a campaign to recur (quarterly or annually) and Vaultic creates and starts the next one automatically once the current one completes — it shows up alongside every other scheduled job on the workspace's Scheduled page.

CLI

See CLI: Workspace, access & tokens for the full vaultic access-review reference — including --mine, the view that makes CLI-based review practical for engineering-led teams who won't open the dashboard.

On this page