Skip to main content
With resource access grants, you can audit and review each grant over time: assign a grantee, record what should happen to it, note why it exists, and schedule when to look again. Every change is kept in a per-grant audit history.

What reviewing adds

Classifying a grant by scope, origin, and trust tells you what the grant is. Reviewing records what your team has decided about it and who is accountable, so the set of grants stays understood as it changes. The review fields and their history form the audit trail for each grant, which you work through in the Audit view and the per-grant Audit tab below. Reviewing is separate from trust. Trust is derived automatically from your trusted principals list; the review fields below are set by people and never change a grant’s trust.

Review fields

Each grant carries four review fields. All four are optional, and every field can be changed at any time. Each change is saved on its own and recorded in the grant’s review history.

Reviewing in Audit view

The grants table has two column layouts, chosen from the view control next to the column options above the table:
  • List shows the default reference columns (mechanism, scope, origin, and the rest).
  • Audit replaces some of those columns with the editable Grantee, Decision, Comment, and Next review fields.
In Audit view you can review grants directly in the table. Edit a cell and the change saves automatically; there is no separate save step. The chosen view is remembered when you reload the page, so you can stay in Audit view while you work through the inventory.
Combine Audit view with the Untrusted external preset and the filter panel to work through the grants most likely to need a decision first.

Reviewing a single grant

Select any row to open the grant’s slide-over, then open the Audit tab. The tab shows the same review fields for that one grant, with Grantee, Decision, and Next review on a single line and Comment below. As in the table, each field saves on its own.

Review history

The Audit tab also shows the grant’s review history below the fields. Each entry records who made a change, when they made it, and what changed, newest first. Because entries capture only the fields that changed, the history reads as a running account of the grant’s review rather than a repeated snapshot.