Daily Access Drift Scan
Run every day at a configured time to compare observed access against approved access across all connected systems, generating new drift findings for any changes since the last scan.
Requires a Nuxari account. Installs as Draft — no changes until you enable it.
Back to templatesWhat this template does
This automation job runs once daily at a configured time and compares the current observed access state against the approved baseline across all connected systems. Any access added, removed, or changed outside an approved workflow since the previous scan surfaces as a new drift finding. Over time it builds a trend record so you can see whether drift is increasing or being controlled.
When to use it
Use this template when daily drift visibility is sufficient and you prefer a predictable, scheduled scan over continuous evaluation. It is a good baseline for organizations that want consistent daily coverage without the overhead of real-time monitoring.
How it works
Scheduled trigger
The job runs at the configured time each day across every connected identity and cloud system in scope.
Access collection
Nuxari collects the current observed access state from each system and compares it against the approved baseline.
Drift detection
Any access added, removed, or changed since the previous scan is identified and recorded as a new drift finding with before-and-after state.
Finding and trend update
New findings are queued for review and the drift trend record is updated so changes over time are visible.
What gets created in your tenant
Daily Drift Scanner
A scheduled job that compares observed against approved access across connected systems each day.
Daily Drift Findings
A findings queue populated by access changes detected since the previous scan.
Drift Trend Overview
A widget showing daily drift counts and trends across connected systems.
What evidence it produces
- Daily access drift scan report
- Per-change drift finding with before and after state
- Scan execution log with timestamps
- Drift trend record over time
Safety and approval model
Templates install as Draft / Disabled by default. No actions run until you explicitly enable the template after reviewing the configuration.
This template installs in Draft state and is read-only — it collects and compares access state but never modifies any access. No scans run until you connect the required connectors and explicitly enable the job. Remediation of drift findings is handled through separate approval-gated workflows.
Customization options
- Scan time of day and timezone
- Connector scope (which systems are included)
- Baseline source (manual definition or identity system import)
- Drift severity thresholds
- Notification routing for new findings
- Trend retention window
Related templates
Access Drift Review
Compare approved access against observed access across connected systems and generate structured findings for any drift — access added, removed, or changed outside an approved workflow.
View templateIdentity Lifecycle Control Pack
Continuously evaluate identity lifecycle governance — new hire provisioning, access baselines, dormant accounts, and offboarding completeness — and generate findings for any gaps.
View templateExcessive Group Membership Review
Detect users assigned to an excessive number of groups or to high-risk groups outside their approved baseline, and generate findings with suggested remediation actions.
View templateUse this template
Install in your Nuxari tenant and run the full approval and evidence workflow from day one.
Build the operating layer
for governance work.
See how Nuxari Ops reduces manual IT work, eliminates access drift, and generates audit evidence automatically, across your entire enterprise.