Access Reconciliation
Learn how Nuxari helps you compare expected and actual access.
Last updated: June 2026
Who this is for
Admins and auditors preparing for access reviews, quarterly audits, or post-incident investigations.
Before you start
At least one connector must be configured and an evaluation must have completed. You need an admin or auditor role to run reconciliation views.
What reconciliation does
Access reconciliation is the process of comparing what access your organization has formally approved against what Nuxari observes in your connected systems. Where the two do not match, Nuxari produces a structured report of mismatches, with context about when the divergence occurred, who is affected, and the magnitude of the gap. Reconciliation is particularly useful before audits, during periodic access reviews, or after organizational changes.
How to review access mismatches
- 1In Nuxari, go to Governance > Reconciliation.
- 2Select the connector or environment you want to reconcile, for example, your identity provider or a specific cloud account.
- 3Nuxari displays a side-by-side view of approved access versus observed access for each user or resource in scope.
- 4Review each mismatch. For each discrepancy, you can: create a remediation plan to correct the observed access, mark it as an accepted exception, or flag it for policy review.
Handling inherited access
Some access comes from group memberships or inherited role assignments rather than explicit grants. Nuxari identifies when observed access traces back to a group membership, so you can see whether the root cause is a direct assignment or a policy-level inheritance. This helps you make the right correction: removing the user from a group rather than just revoking an individual permission.
How reconciliation supports audit preparation
During an audit, your reviewers will typically ask: who has access, was it authorized, and has any unauthorized access been corrected? Nuxari's reconciliation view answers the first two questions directly. When combined with evidence packages and the audit log, you have a complete, time-ordered record to support every access decision your organization made.