Campaign shape
Reviewer experience
Reviewers see one identity per row with:- Kind, source, name, last used, current permissions
- The owner-of-record and any recent findings
- Prior attestations
- Three buttons: Certify, Modify (open a change ticket), Revoke
j / k to move and 1 / 2 / 3 to decide — designed for campaigns with hundreds of rows.
Evidence export
At close, the campaign auto-generates:- A machine-readable JSON export (one row per identity, per decision, per reviewer).
- A signed PDF summary with campaign metadata and per-reviewer sign-off.
- A per-identity audit-log trail linking the campaign, the decision, and the resulting change (revocation, policy diff, ticket).
Continuous vs discrete campaigns
- Discrete — one scope, one deadline. Good for annual SOC 2 evidence.
- Continuous — every new identity in scope gets added to the current window; reviewers see a rolling backlog. Good for operational drift control.
Related
Findings
Findings feed into the next campaign automatically.
Ownership
Reviewers are usually owners — attestation counts as a review.