How to Run a User Access Review

How to Run a User Access Review

Overview

The User Access Coverage tab in Asset Inventory shows which of your connected systems each user exists in. Use it for periodic access reviews, joiner/mover/leaver checks, and to spot accounts that were never removed.

The tab has two parts: a table of every user against every connected source, and a per-user access graph you open by clicking a row.


Prerequisites

  • At least one connected source that reports users (for example a directory, an identity provider or a mail platform), with a completed scan
  • defence:dashboard:view to open Asset Inventory
  • defence:widget:view, which is what the access-review data is served under

Opening the Review

Navigation: Sidebar → Assets → Asset Inventory → User Access Coverage

  1. In the sidebar, expand Assets and click Asset Inventory.
  2. Select the User Access Coverage tab.

The table loads with the heading User Access Coverage.


Reading the Table

Each row is one user. The first three columns are fixed; after them there is one column per connected source.

ColumnWhat it shows
EmailThe user's email address. This is the identity the row is keyed on.
User TypesThe user's type values, shown as chips.
User GroupsThe groups the user belongs to, shown as chips.
One column per sourceA tick if that source knows this user, an exclamation mark if it does not.

Because the source columns come from whatever you have connected, the table gets wider as you add integrations.

Narrowing the list

Filters sit in the column headers:

  • Email — type into the header filter to match part of an address.
  • User Types — pick from a dropdown of the values present in your data.
  • User Groups — pick from a dropdown of the groups present in your data.

The table is paginated; use the page controls at the bottom to move through users.


Looking at One User

  1. Click any row in the table.
  2. A window opens showing User Access Coverage for that user, with the subtitle *"Visualize how user access propagates across your asset topology."* and the user's email in the corner.
  3. The user's access is drawn as a graph: each box is one attribute or resource, and the lines show how they connect. Drag to pan, use the zoom controls in the top right, and use the small overview map to keep your place in a large graph.
  4. Click Close to return to the table.

If nothing has been recorded for that user, the panel reads "No user access coverage found" with the hint *"Try selecting a different user."*


Using It for an Access Review

  • Work down the table looking for users who appear in more systems than their role needs.
  • Cross-check your leavers list against the Email column: a leaver still ticked in several sources has not been fully de-provisioned.
  • Filter by User Groups to review one team or one privileged group at a time.
  • Open the graph for anyone whose row looks unusual before you raise it — the graph shows what the tick actually represents.

Troubleshooting

No users are listed → No connected source has reported users yet. Connect a source that carries user data under Admin > Integrations and let its scan finish.

A user is missing entirely → The table is built only from what your connected sources report. If no connected source knows that account, it will not appear.

A user looks like they have less access than you expect → Coverage reflects connected sources only. Systems you have not integrated are invisible here, so an account can look narrower than it really is.

There is no export button on this tab → Export is not offered on the User Access Coverage table. Use the page filters to narrow the view, or build a widget over the user data if you need a downloadable extract.

I opened the tab but the columns are only Email, User Types and User Groups → Source columns only appear once at least one source has reported users. Check that your integrations have completed a scan.


Need more help? Contact support@zeron.one