Skip to content
English - United States
  • There are no suggestions because the search field is empty.

Access Reviews

Learn how to create, manage, and use Access Reviews

Published Date: June 16, 2026 | Last Updated: July 15, 2026

Overview

Access Reviews allow Administrators to run structured certification campaigns that verify whether users’ current access is appropriate. Each campaign is scoped to one or more teams and assigned to a designated reviewer — typically a team manager or department lead — who logs in to Tello IAM, reviews each team member’s permissions, and approves or flags anything that needs attention.

Access Reviews can currently be scoped by team. Review by integration is planned for a future release.

Access Review roles

Three administrative roles control who can create and participate in Access Reviews. These roles are assigned when inviting or editing an administrator account and do not grant access to any other area of the platform.

Role Description
Access Review Admin Can administer all access review campaigns across the tenant.
Access Review Creator Can create access reviews and manage their own campaigns.
Access Review User Can participate in assigned access reviews. Intended for reviewers such as team managers who need to log in to Tello IAM to complete a review without access to administrative functions.

Note: Full Administrators have access to all Access Review functions by default.

Create an access review

New access reviews are saved as a Draft. No notifications are sent to reviewers until the review is explicitly sent.

  1. Navigate to Access Reviews in the left navigation.
  2. Select + New Access Review.
  3. Select Review by team as the scope.
  4. Enter a name in the Name field.
  5. Set the Due date.
  6. Under Teams to review, select + Add a team and choose the teams to include. Each team displays a suggested reviewer. To change the reviewer, select the reviewer dropdown and choose a different user.
  7. Select Create review. The review is saved as a Draft and the detail page opens.

Note: If a reviewer does not have a Tello IAM account, a No Tello IAM account warning will appear on the review detail page. Tello IAM can automatically send the reviewer an account invitation when the review is sent.

Edit a draft review

While a review is in Draft status it can be modified before sending. Select Edit draft on the review detail page to change the name, due date, teams, or reviewer assignments. Select Save changes to apply updates.

Send an access review

Sending a review changes its status from Draft to Active and notifies the assigned reviewers.

  1. From the review detail page, select Send review.
  2. The Send Access Review dialog displays the reviewers who will be notified. Any reviewer without a Tello IAM account is shown with a Will be invited to Tello IAM badge.
  3. Review the pre-populated notification message. The message can be edited before sending.
  4. To automatically send an account invitation to any reviewer who does not yet have a Tello IAM account, confirm the Invite reviewers to Tello IAM as needed toggle is enabled.
  5. Select Send Email to send notifications and activate the review.

Reviewer email notifications

When a review is sent, the assigned Reviewer receives email from noreply@telloiam.cloud. Depending on the Reviewer’s account status, this is 1 or 2 emails.

Account invitation

If the Reviewer does not yet have a Tello IAM account and the Administrator enabled the Invite reviewers to Tello IAM as needed option when sending the review, the Reviewer receives an account invitation with the subject [Tello IAM] You've been invited. The Reviewer selects Accept Invitation in the email to begin account setup.

Note: The invitation expires 7 days after it is sent. An expired invitation can be resent by the Administrator.

Review assignment notification

The Reviewer also receives an assignment notification with the subject Action required: Complete the [Review Name]. This email contains everything the Reviewer needs to begin:

  • Requesting Administrator — the name and role of the Administrator who assigned the review
  • Message — the notification message written by the Administrator when the review was sent, including any stated deadline
  • Review summary — the review name, the Reviewer’s scope (number of users to review), the start date, and the due date
  • Start Access Review — a button that signs the Reviewer in to Tello IAM and opens their assignment

Reviewer account setup

This section applies to Reviewers accessing Tello IAM for the first time through an account invitation. Reviewers who already have a Tello IAM account skip directly to their assignment.

Note: Everyone accessing Tello IAM must set up two-factor authentication (2FA) before proceeding. This applies to all account types, including Reviewers.

Set up the authenticator

After selecting Accept Invitation, the platform opens the Authenticator Setup page and displays You need to set up Mobile Authenticator to activate your account.

  1. Install an authenticator app on a mobile device. Any standard authenticator app works, including Google Authenticator, Microsoft Authenticator, Duo, and Proton Authenticator.
  2. Open the authenticator app and scan the QR code displayed on the Authenticator Setup page. If the device cannot scan the code, select Unable to scan? to enter the setup key manually.
  3. Follow the prompts to confirm the authenticator is registered.

Set a password

The platform proceeds to the password screen and displays Set a password to complete your account setup.

  1. Enter a password in the New Password field.
  2. Enter the same password in the Confirm Password field.
  3. Select Reset Password.

Password recommendation: Tello IAM contains sensitive access and identity information. Use a unique password that is not used for any other account. We recommend a password of at least 15 characters containing uppercase letters, lowercase letters, numbers, and symbols.

Confirmation: The platform displays Done. Your account has been updated. Select Continue to sign in to proceed to the sign-in screen.

Sign in

  1. Enter the account email address in the Email field.
  2. Enter the password in the Password field.
  3. Select Sign in.
  4. On the Verify it's you screen, enter the 6-digit code from the authenticator app in the Verification code field.
  5. Select Verify.

Confirmation: The Reviewer is signed in to Tello IAM.

Completing the review

This section describes the review process from the Reviewer's perspective. Reviewers with the Access Review User role see a simplified platform — the left navigation contains only Access Reviews, with no access to administrative functions.

The Access Reviews page

After signing in, the Reviewer lands on the Access Reviews page, which lists every review assigned to them. Tabs filter the list by All, Active, and Completed. Each row displays:

  • Name — the review name
  • Users — the number of users in the Reviewer's scope
  • Progress — percentage of the assignment completed
  • Status — the review status (Active or Completed)
  • Started and Due — the review dates

Select a review to open the assignment.

The review assignment page

The assignment page shows the review scope on the left and the selected user's access on the right. The header displays the total users in review, submitted and pending counts, the start date, and the due date.

The left panel lists each user in the assignment with a status indicator — an open circle for pending, a green check for submitted. Tabs filter the list by All, Pending, and Submitted, and the Find user field searches by name.

The right panel displays the selected user's access grouped by integration. The By Role and By System toggles organize the access by Role Template or by integration. Each entry shows the integration, the specific permission (for example, a group membership or role), and its source — a Role Template or Ad Hoc access.

Reviewing each user's access

For each permission, the Reviewer has 3 options:

  • Accept — take no action on the permission. All permissions without a suggestion are accepted when the user's review is submitted
  • Add suggestion — the mechanism for disputing access or requesting a change. Use a suggestion for anything that should not simply be approved: access that should be removed, access that looks wrong, or access the Reviewer needs IT to investigate
  • Comment — ask a question or add context without disputing the access

To add a suggestion:

  1. Select Add suggestion on the permission row. The Add Suggestion dialog opens, identifying the integration and permission being addressed.
  2. Describe what should change about the access and why in the Suggestion field.
  3. Optionally attach supporting files under Attachments (PNG, JPG, PDF, or EML, up to 10 MB each).
  4. Select Save.

Confirmation: The platform displays Change Suggested. The permission row is highlighted with an Open Suggestion indicator. Select the indicator to view, Edit, or Delete the suggestion before submitting.

To comment on a permission, select the comment icon on the permission row, enter the comment, and select Send. Comments support @-mentions and attachments. The Comments panel shows the full conversation on each permission, including replies from Administrators, and is searchable.

Submitting a user's review

  1. When every permission for the user has been reviewed, select Submit & Next.
  2. The Submit review dialog displays a summary: the number of systems and permissions reviewed, how many permissions are accepted, and how many suggestions were made.
  3. Optionally add a note for the review owner in the Note field.
  4. Select Submit review.

Confirmation: The platform displays Review Submitted. Your attestation has been recorded. The user's status indicator changes to a green check, the progress counters update, and the platform advances to the next pending user.

Note: Submitting a user's review records a formal attestation. Permissions without suggestions are accepted, and any suggestions are sent to the review owner. Repeat the process for each user until every user in the assignment is submitted.

After the assignment is submitted

When the last user is submitted, the assignment page shows 0 users on the Pending tab, every user with a green check and a Submitted badge, and the progress indicator at full. On the Reviewer's Access Reviews page, the review displays 100% progress with a status of Submitted.

Note: Submitted and Completed are distinct statuses. A submitted review reflects that the Reviewer has finished their attestations; the review remains active until the Administrator closes the campaign with Complete review. The Reviewer's Completed tab updates only after the Administrator completes the review.

Monitor review progress

Once a review is Active, the review detail page displays a live summary of progress across three panels.

  • The Review Status panel shows percentage complete and a breakdown of users by status: Completed, Needs action, and Pending.
  • The Reviewers Remaining panel shows how many assigned reviewers have not yet submitted.
  • The Due panel shows the days remaining and due date.

The reviewer table below the summary panels lists each reviewer with their assigned user count, a progress indicator, and a current status. Tabs above the table filter the list by Needs action, Completed, and Pending reviewer.

Selecting Open › on any reviewer row opens that reviewer’s full assignment. The detail view shows each assigned user on the left and their access on the right, organized either by Role Template (By Role) or by integration (By System). Each user’s record indicates whether the reviewer has submitted a decision.

Review submitted results

Tello IAM does not send a notification when a Reviewer completes their assignment. The Administrator monitors completion from the review detail page, where the 3 summary panels reflect the outcome.

  • The Review Status panel shows 100% complete, with users broken down into Completed (all permissions accepted) and Needs action (1 or more suggestions submitted)
  • The Reviewers Remaining panel displays All reviewers completed
  • The reviewer table shows each reviewer's final tally — accepted users, users needing action, and pending — with a status of Needs action if any suggestions require the Administrator's attention

Select Open › on the reviewer row to work through the suggestions. Each user's detail shows who reviewed them, the submission date, the number of suggestions, and the Reviewer's submission note. The left panel filters users by All, Needs action, Pending, and Completed — an orange dot marks users with open suggestions. Comments left by the Reviewer are visible on each permission.

Resolve a suggestion

Permissions with an open suggestion are highlighted with an Open Suggestion indicator. Select the indicator to view the suggestion, then select Resolve. 3 resolution options are available:

  • Edit Access — change the user's access in the connected system. The Resolve suggestion dialog displays the suggestion and an editor for the permission. Current values appear as removable entries, and the Add dropdown lists the values available in the connected system. Select Apply changes to execute the change
  • Dismiss — keep the access as-is and close the suggestion. The permission displays a Suggestion Dismissed indicator
  • Mark resolved externally — close the suggestion because the change was made outside Tello IAM

Applying changes creates a provisioning task against the connected system. The task record shows the type, integration, requesting Administrator, start and completion times, duration, and the grants requested. If the connected system rejects the change, the task displays a Failed status with the error returned by the integration — verify the result rather than assuming the change applied.

As suggestions are resolved, the review counters update — when no open suggestions remain, users move from Needs action to Completed and the reviewer's status displays Completed.

Send a reminder

To follow up with reviewers who have not yet completed their assignment, select Send reminder from the review detail page. The Send Access Review Reminder dialog works identically to the initial send: confirm which reviewers to notify, edit the message if needed, and select Send Reminder.

Complete a review

Completing a review is a manual, final action available only to the review owner. Reviews do not complete automatically — when all review work is finished, the review remains Active until the owner completes it.

  1. From the review detail page, select Complete review.
  2. The Complete Access Review dialog confirms whether all review work is finished and states: Complete this review? This makes the campaign read-only.
  3. Select Complete review to finalize the campaign and record the results.

Confirmation: The review detail page displays a banner: Review completed [date]. This campaign is read-only. The review's status badge changes to Completed and it moves to the Completed tab on the Access Reviews list.

Important: Completing a review is irreversible. The campaign becomes read-only and its results are recorded permanently. Resolve all open suggestions before completing.

Completed reviews remain visible in the Access Reviews list and can be filtered using the Completed tab.

Related articles

  • Managing Administrators — assign and update administrative roles including Access Review roles
  • Teams — create and manage the teams used as the scope for access reviews


tello-logo-color-1 Seasoft Security Solutions LLC | TelloIAM