Access Drift Review
Compare approved access against observed access across connected systems and generate structured findings for any drift — access added, removed, or changed outside an approved workflow.
Requires a Nuxari account. Installs as Draft — no changes until you enable it.
Back to templatesWhat this template does
This automation job collects the observed access state across connected systems and compares it against an approved baseline — either manually defined or imported from an identity source. Any access that was added, removed, or modified outside an approved Nuxari workflow surfaces as a drift finding. Each finding records the before-and-after state and the system in which the drift occurred.
When to use it
Use this template when you need ongoing assurance that access changes only happen through approved workflows. It is especially valuable in environments where administrators can make direct changes in native portals, creating drift that bypasses governance.
How it works
Baseline definition
The approved access baseline is established either by manual definition or by importing approved state from a connected identity system.
Observed access collection
Nuxari collects the current observed access from each connected system on its configured schedule.
Comparison and detection
Observed access is compared against the baseline. Additions, removals, and changes outside an approved workflow surface as drift findings.
Finding generation
Each drift finding records the system, the affected identity, and the before-and-after access state for review and remediation.
What gets created in your tenant
Access Drift Scanner
A job that compares observed access against the approved baseline across connected systems.
Access Drift Findings
A findings queue populated by access that diverges from the approved baseline.
Drift Review Evidence
Structured evidence records capturing baseline, observed state, and detected drift.
What evidence it produces
- Access drift findings with before and after state
- Approved baseline snapshot
- Observed access snapshot per system
- Drift summary report by system and severity
Safety and approval model
Templates install as Draft / Disabled by default. No actions run until you explicitly enable the template after reviewing the configuration.
This template installs in Draft state and is read-only — it compares access state but never modifies any access. No scans run until you connect the required connectors and explicitly enable the job. Remediation of drift findings is handled through separate approval-gated workflows.
Customization options
- Baseline source (manual or identity system import)
- Connector scope (which systems are compared)
- Drift severity thresholds
- Scan frequency (continuous, daily, weekly)
- Notification routing for new drift findings
- Allowed-change exclusions for expected variance
Related templates
Identity Lifecycle Control Pack
Continuously evaluate identity lifecycle governance — new hire provisioning, access baselines, dormant accounts, and offboarding completeness — and generate findings for any gaps.
View templateExcessive Group Membership Review
Detect users assigned to an excessive number of groups or to high-risk groups outside their approved baseline, and generate findings with suggested remediation actions.
View templateDaily Access Drift Scan
Run every day at a configured time to compare observed access against approved access across all connected systems, generating new drift findings for any changes since the last scan.
View templateUse this template
Install in your Nuxari tenant and run the full approval and evidence workflow from day one.
Build the operating layer
for governance work.
See how Nuxari Ops reduces manual IT work, eliminates access drift, and generates audit evidence automatically, across your entire enterprise.