User Access Reviews for Reviewers
Conduct a User Access Review for your Team, Department, or System
Published Date: July 20, 2026 | Last Updated: July 20, 2026
Overview
This guide is for Reviewers — managers, team leads, and process owners who have been asked to complete a User Access Review in Tello IAM. No prior experience with Tello IAM is required. This guide covers what an access review is, the emails the Reviewer receives, setting up an account for the first time, and completing the review from start to finish.
What an access review is
Tello IAM is the platform the IT team uses to manage which applications and permissions each employee has. An access review is a periodic check where someone who knows the team — the Reviewer — confirms that each person's current access is still appropriate. The Reviewer looks at what each assigned team member can access, confirms what is correct, and raises anything that looks wrong or unclear.
The review is a formal attestation. Submitted decisions are recorded and form part of the organization's audit record.
3 terms appear throughout the review:
- System — a connected application, such as HubSpot, Asana, or Microsoft 365
- Permission — what the person can do or access within a system, shown as a role or group membership
- Suggestion — the Reviewer's mechanism for raising a concern about a permission. A suggestion says: this access should change, or IT should look at this
The emails
Review notifications come from noreply@telloiam.cloud. The Reviewer receives 1 or 2 emails.
Review assignment notification
Every Reviewer receives an email with the subject Action required: Complete the [Review Name]. It identifies who assigned the review, includes their message, and summarizes the assignment: the review name, how many users to review, the start date, and the due date. Select Start Access Review in the email to sign in and begin.
Account invitation
Reviewers who do not yet have a Tello IAM account also receive an invitation with the subject [Tello IAM] You've been invited. Select Accept Invitation to set up the account — see the next section.
Note: The invitation expires 7 days after it is sent. If it has expired, contact the person who assigned the review — they can resend it.
First-time account setup
This section applies only to Reviewers accessing Tello IAM for the first time. Reviewers with an existing account can skip to Completing the review.
Note: Everyone accessing Tello IAM must set up two-factor authentication (2FA) before proceeding. 2FA protects the account with a second step at sign-in: a 6-digit code from an app on the Reviewer's phone, in addition to the password.
Step 1: Set up the authenticator
After selecting Accept Invitation, the Authenticator Setup page opens and displays You need to set up Mobile Authenticator to activate your account.
- Install an authenticator app on a phone. Any standard authenticator app works — Google Authenticator, Microsoft Authenticator, or Duo. If the organization already uses one, use that.
- Open the authenticator app and use it to scan the QR code shown on the Authenticator Setup page. The app adds a Tello IAM entry that generates a new 6-digit code every 30 seconds.
- If the phone cannot scan the code, select Unable to scan? and enter the setup key manually.
- Follow the prompts to confirm the authenticator is registered.
Step 2: Set a password
The platform proceeds to the password screen and displays Set a password to complete your account setup.
- Enter a password in the New Password field.
- Enter the same password in the Confirm Password field.
- Select Reset Password.
Password recommendation: Tello IAM contains sensitive access information. Use a unique password that is not used for any other account. We recommend a password of at least 15 characters containing uppercase letters, lowercase letters, numbers, and symbols.
Confirmation: The platform displays Done. Your account has been updated. Select Continue to sign in.
Step 3: Sign in
- Enter the account email address in the Email field.
- Enter the password in the Password field.
- Select Sign in.
- On the Verify it's you screen, open the authenticator app and enter the current 6-digit code in the Verification code field.
- Select Verify.
Confirmation: The Reviewer is signed in to Tello IAM.
Finding assigned reviews
After signing in, the Reviewer lands on the Access Reviews page, which lists every review assigned to them. Reviewer accounts see only this page — no other part of the platform is accessible.
Each review shows its name, the number of users to review, a progress bar, its status, and the start and due dates. Tabs filter the list by All, Active, and Completed. Select a review to open it.
Understanding the review page
The review page has 2 parts.
The left panel lists every person in the assignment. An open circle means the person has not been reviewed yet; a green check means their review is submitted. Tabs filter by All, Pending, and Submitted, and the Find user field searches by name.
The right panel shows the selected person's access, grouped by system. Each entry shows the system, the specific permission, and where the access came from — a Role Template (a standard set of access assigned by IT for their job) or Ad Hoc (access granted individually). The By Role and By System buttons switch between grouping by Role Template and grouping by system.
The header shows overall progress: total users, how many are submitted, and the due date.
Completing the review
Review each person one at a time. For each permission, there are 3 possible actions:
- Accept — if the access is appropriate, take no action on it. Every permission without a suggestion is accepted when the person's review is submitted
- Add a suggestion — if the access looks wrong, should be removed or changed, or needs IT's attention. A suggestion does not change anything immediately — it is sent to the review owner, who investigates and makes any changes
- Comment — to ask a question or add context without disputing the access
Important: Accepting is the default. Submitting a person without any suggestions accepts all of their access. Review each permission deliberately before submitting — the submission is a recorded attestation that the access is appropriate.
Add a suggestion
- Select Add suggestion on the permission row. The Add Suggestion dialog opens, showing which system and permission it applies to.
- Describe what should change and why in the Suggestion field. Plain language is fine — for example: "Jason is moving from LA to Boston. This should change to East Region as of August 1."
- Optionally attach supporting files (PNG, JPG, PDF, or EML, up to 10 MB each).
- Select Save.
Confirmation: The platform displays Change Suggested and the permission is marked Open Suggestion. Select the marker to Edit or Delete the suggestion before submitting.
Note: Unsure what a permission is or whether it is appropriate? That is a valid finding. Add a suggestion saying so — for example, "I don't recognize this group. Can IT confirm what it grants?" — and IT will follow up. Do not accept access that cannot be vouched for.
Add a comment
Select the comment icon on a permission row, write the comment, and select Send. Comments support @-mentions and attachments, and the review owner can reply. Comments are conversation — they do not affect whether the access is accepted.
Submit each person
- When every permission for the person has been considered, select Submit & Next.
- The Submit review dialog summarizes the decision: how many permissions are accepted and how many suggestions were made.
- Optionally add a note for the review owner in the Note field.
- Select Submit review.
Confirmation: The platform displays Review Submitted. Your attestation has been recorded. and advances to the next pending person. Repeat until every person is submitted.
After the review
When the last person is submitted, the Pending tab shows 0 and the review displays 100% progress with a status of Submitted. The Reviewer's work is done.
The review owner then works through any suggestions — making changes, following up with the Reviewer, or resolving items with IT — and closes the review. Suggestions and comments may generate follow-up questions, so watch for replies from the review owner.
Getting help
If the Reviewer encounters an issue or requires assistance, the following resources are available:
- The review owner — for questions about the review itself: scope, deadlines, or what a permission means. The assignment email identifies who assigned the review
- In-platform feedback — select the Feedback tab on the right edge of any page to submit a message directly from the platform
- Support — contact the Tello support team for account issues, access problems, or technical questions at Support@SeasoftSecurity.com
Seasoft Security Solutions LLC | TelloIAM