Skip to main content

Governance intelligence for access, cloud, and SaaS. Now in early access

Nuxari
PlaybookEvidence & Compliancemedium riskApproval required

Quarterly Access Recertification

Run a structured quarterly access review across connected systems. Collect manager attestations, route exceptions to approval, and produce a complete evidence package ready for auditors.

Compliance and GRC teamsIT security teams preparing for SOC 2 auditsOrganizations with annual or quarterly access review requirementsMSPs delivering compliance services to clients
Use template

Requires a Nuxari account. Installs as Draft — no changes until you enable it.

Back to templates
~30 min setup
Required
Entra ID

What this template does

This playbook runs a structured access recertification campaign on a configurable schedule (default: quarterly). At the start of each campaign, it collects a full snapshot of user access across connected systems and groups it by manager. Each manager receives an attestation task listing their direct reports and the access each person holds. Managers confirm, flag for review, or revoke access. Flagged items enter an exception workflow requiring approver sign-off. Confirmed removals are executed with evidence. The campaign closes with an auditor-ready evidence package.

When to use it

Use this template if your organization needs to demonstrate periodic access review as part of SOC 2, ISO 27001, HIPAA, or similar compliance frameworks. It replaces manual spreadsheet-based access reviews with a fully automated, evidence-generating workflow that produces documentation auditors can verify independently.

How it works

01

Access snapshot

At campaign start, Nuxari collects a timestamped snapshot of all user access across connected systems and organizes it by reporting manager.

02

Manager attestation

Each manager receives an attestation task with a list of their direct reports and the access each person holds. Managers confirm, flag for review, or request revocation for each item.

03

Exception handling

Items flagged for review enter an exception workflow. The exception is routed to the configured approver with the manager's justification and a recommended action.

04

Approval-gated remediation

Access revocations confirmed by managers or approved via the exception workflow are executed with approval records attached to each action.

05

Evidence package export

On campaign close, a full evidence package is generated: access snapshots, attestation responses, exception records, approval decisions, remediation actions, and a completion certificate.

What gets created in your tenant

Playbook

Access Recertification Campaign

The core campaign playbook that drives the full recertification lifecycle from snapshot through evidence export.

Attestation Campaign

Manager Access Attestation

Structured attestation tasks sent to each manager with their team's access inventory.

Approval Workflow

Exception Approval Gate

An approval workflow for access items flagged as exceptions during the attestation phase.

Evidence Package Template

Recertification Evidence Package

A structured evidence package capturing every phase of the campaign, exportable as PDF or JSON.

Scheduled Job

Quarterly Campaign Trigger

A time-triggered job that launches a new recertification campaign on the configured schedule.

What evidence it produces

  • Full access inventory snapshot at review start
  • Manager attestation responses with timestamps
  • Exception list with justification records
  • Approval decisions for each exception
  • Remediation action log for revoked access
  • Recertification completion certificate
  • Auditor-ready evidence export (PDF and JSON)

Safety and approval model

Templates install as Draft / Disabled by default. No actions run until you explicitly enable the template after reviewing the configuration.

This template requires an approval decision before enabling. No execution occurs without a recorded approver sign-off.

This template installs in Draft state. No campaigns run, no attestation tasks are sent, and no access is modified until you configure the connector scope, attestation chain, and explicitly enable the playbook. Access revocations require approval and cannot be executed without a recorded approval decision. All attestation tasks, responses, and approval decisions are logged with full timestamps and actor identity.

Customization options

  • Campaign frequency (quarterly, semi-annual, annual, or custom)
  • Connector scope (select which systems are included in the review)
  • Attestation deadline and reminder schedule
  • Exception workflow routing and approval chain
  • Evidence export format (PDF, JSON, or both)
  • Manager notification channel (email, Teams, or Slack)

Use this template

Install in your Nuxari tenant and run the full approval and evidence workflow from day one.

Use template
Get started

Build the operating layerfor governance work.

See how Nuxari Ops reduces manual IT work, eliminates access drift, and generates audit evidence automatically, across your entire enterprise.