Documentation Index

Fetch the complete documentation index at: https://help.scrut.io/llms.txt

Use this file to discover all available pages before exploring further.

Quick Start Guide: Access Reviews

Prev Next

Step-by-step guide to conduct access reviews in Scrut.

Set up the Review

Navigate to People → Access Reviews to start. Use the Reviews, Applications, and Access Chart tabs to manage and review access data.

Step 1: Create and Assign Ownership. Start by creating a new access review in Scrut and designating a review owner who will oversee the entire process.

Step 2: Set the Timeline. Define the expected review time in days (e.g., 30 days). This gives everyone involved a clear deadline to work with.

Step 3: Choose Review Frequency. Decide how often this review should happen. You can set it to run once, monthly, quarterly, semiannually, or annually, based on your compliance requirements.

Step 4: Select Applications. Choose which applications you want to be included in this access review. This determines the scope of what will be examined.

Step 5: Assign Roles. For each selected application, assign two key people:

  • A reviewer who will examine user permissions and make necessary changes

  • An approver who will verify and approve the reviewer's actions

Conduct the Review

Step 1: Automatic Data Collection. Once the review goes active on the scheduled date, Scrut automatically pulls in the complete user list and their assigned roles from each application you've included.

Step 2: Reviewer Assessment. The assigned reviewer examines each user's access and can decide to:

  • Approve: Keep current access as-is

  • Modify: Change permissions or roles

  • Revoke: Remove access entirely

Step 3: [Optional] Create Tickets for Access Changes. You can create tickets in Scrut and assign them to specific users in your ticket management platform.

Step 4: Send for Approval. Once the reviewer has completed their tasks, they can send them to the approver for verification.

Step 5: Approver Verification. After the reviewer completes their assessment, the approver reviews all the decisions and either approves or requests changes.

Step 6: Owner Conclusion. Once all applications have been reviewed and approved, the review owner officially concludes the entire process.

Post Review Completion

Automatic Evidence Generation. Scrut automatically creates compliance evidence showing that your organization completed access review for all applications in scope. This documentation gets attached to your control tests, providing proof of your access review completion for all in-scope applications for audit purposes.

This systematic approach ensures that user access across your organization is regularly reviewed, properly documented, and aligned with your security and compliance requirements.