Feature - Account Reviews

Migration of form and views

Account Review Tab

Form:

  • Form will have 1 tab. The feed tab will be merged into the general tab, and the portal setting tabs will be removed.
  • The feeds will be all non-cas sensitive by default.
  • Frequency fields should be similar to the internal controls audit, where you select the first date and then you select the frequency.
Field Mandatory Hidden Notes
Title Yes
Description No
GRC Contact Yes
Reviewer Contact Yes
Type Yes
Feed Yes Feeds will be always non-case sensitive.
Exit feed Yes if “Feed” is set to “Exit” The field will be hidden unless “Feed” is set to “Exit”
Frequency Yes Same field as IC Audits (first audit date + frequency drop-down)
Assets No Yes
Tags No Yes

Default View

Field Description
Dynamic Status
Title
Latests Findings It will be displayed the number of findings from the latest pull. Once there is a new pull, if they were not reviewed, they go to the column, “Missing Reviews”.
Missing Review It will be displayed the number of findings that still weren’t reviewed from the previous pulls.
GRC Contact
Reviewer Contact
Last Pull Field with the date of the last pull. (is it all for trigger pull or only for scheduled pull?)
Next Pull Field with the date of the next pull.
Type
Feed The name of the feed being used. Both exit and regular if applicable

Pinned Views

View Description
All Items All Account reviews
Started All account reviews that are started.
Stopped All account reviews that are stopped.
Pending Reviews Pending reviews field > 0
Reviewed Pending reviews <= 0
Findings Open Findings =>1

Notifications

Report

Create report notification, every 7 days, pdf+csv for:

View Recipient
Started Admin (TO BE REVIEWED)
Stopped Admin
Pending Reviews Admin
Reviewed Admin
Findings Open Admin

Warning

Name Recipients Conditions Variations Enabled
Item Created GRC Contact, Reviewer New item created. No
Item Edited GRC Contact, Reviewer Item has been added. No
Item Deleted GRC Contact, Reviewer Item has been deleted. No

Comments & Attachments

Name Recipients Conditions Variations Enabled
New Comment & Attachment GRC Contact, Reviewer New Comment & Attachment No

Dynamic Status

Name Description Variations Enabled
Finding expired At least one related Account Review Pull finding is expired and is still active. Yes
Open finding At least one related Account Review Pull finding is open and active. Yes
Latest pull failed Last pull failed or automation failed Yes
Pending Reviews Pull found accounts that are pending review (they are neither "Reviewed or “Not Reviewed” Yes
Reviewed All pull feedback has been marked as “Reviewed”. Yes
Not Reviewed 1 or more account marked as not “Not Reviewed”. Yes
Started Account is started Yes
Stopped Account review is stopped Yes

Action Bar

  • The “trigger pull” button will be changed to “Trigger Review”.
    • When the button is clicked, the warning modal will be shown with the following text:
By clicking **“Submit”**, the account review will be triggered immediately and the system will look for findings right away.

This manual trigger is independent of your configured account review periodicity, so it will run regardless of when the next scheduled review is due.

The “Latest Finding” column will be updated with the findings identified during this review. If there are any accounts currently listed there still requiring review, they will first be moved to the 
“Missing Review” field before the new findings are recorded.
  • The portal URL button will be changed to “Review Findings”.
    • This button will go to the feedback tab (where do you do account reviews) with a filter applied will only the findings from the latest pull and from the account review that you are coming from to the account review that you are coming from.

Feeds

Form

Field Mandatory Hidden Notes
Title Yes
Description No Yes
Source Yes 1. For new install, only “Automation” will be shown. If possible, the field should be disabled. That way we don’t have a dropdown with only one option. 2. For previous installs we will still show file, aws, and LDAP, but there will be this message next to them. “This option is being deprecated. Please do not use it, as it will be removed soon.”

The rest of the fields that show up based on the type of the source will remain the same.

Default View

Field Description
Dynamic Status
Title
Source Type of sorce feed file,aws,automation…
Type List of current employees, List of accounts to be reviewed, List of former employees

Pinned Views

View Filter
All Items All feeds
List of current employees Type = List of current employees
List of accounts to be reviewed Type = accounts to be reviewed
List of current employees Type = current employees

New “Test” Button

The form should include a Test button for the feed.

The feed is already tested when the form is saved, but we need a separate “Test” button that displays the feed output. If the feed is very large, only the first 10 rows should be shown.

If the feed has already been tested using Test button, then clicking Save again should not re-test the feed.

However, if the user clicks Save without testing the feed first, the Save button should still run the feed test before saving.

Action Bar

The download button will be removed, and it should be replaced by a test button. The test button should open a modal that will run the test and then show the output of the feed. Like testing the automation

Pulls And Audit trails (ON HOLD, DON’T DEVELOP YET)

These sections will be both merged into “Audit Trails”

Default View

Field Description
Dynamic Status
Account Review Account review name
Type Pull failed, Pull succeeded, Reviewer Action
Accounts Real user, empty value, or clickable (see section below)
Logs Main result or action message (see section below)
Date Pull / audit trail date

Row rules

Case Accounts Logs Click behavior
Pull failed because automation failed Empty Automation Log (number) Clicking the number will open bottom drawer with automation logs, same as on feeds now
Pull succeeded Empty 1 Clicking “1l” opens bottom drawer (see section below)
Reviewer action Reviewer name Reviewer action message NA
Pull failed for missing fil Empty The pull process failed because the feed file does not exist. NA

Drawer for Pull Trail
Clicking Pull Trail will open bottom drawer and you will see the following columns.

Pinned Views

View Filter
All Items All Account audit trails
Pull succeeded Type=Pull succeeded
Pull failed Type=Pull failed
Reviewer Action Type=Reviewer Action

Feedbacks

The account review portal will be removed, and all the reviewing of the accounts will be done on the feedback section. For each account review created will have its own dedicated view, similar to how Compliance Analysis and Compliance Packages currently work.

possible statuses:

Default View

Field Description
Dynamic Status
Account Review The name of the account review that the the feedback belongs to
Account Name of the account found (ex: adrian.santa)
Issue What was detected on the account, for example: Created, Deleted, Role Change, Creeping (Exit discrepancy)
Roles If there are role changes, then they will be displayed on this column, for example +Support, -Admin with colors if possible. (See Explicit visual differentiation for reviews. )
Notes
Reviewed Reviewed/Not Reviewed
Reviewed Date

Pinned Views

View Filter
All Items All Account reviews feedbacks
Reviewed All feedbacks reviewed
Not Reviewed All feedbacks not reviewed
x (Account review Name) one view for every account review that filters for their feedback, like compliance packages and compliance analysis

Dynamic Status

Name Description Variations Enabled
Reviewed Reviewed = true Yes
Not Reviewed Not Reviewed = true Yes
Finding Expired Account Review Finding - Finding Expired Is active Yes
Open Finding Account Review Finding - Open Finding Is active Yes

Notifications

Warning

Name Recipients Conditions Variations Enabled
Accounts need to be reviewed on {$name} GRC Contact, Reviewer Latest pull found accounts. Yes
Accounts review overdue - {$name} GRC Contact, Reviewer Pull found accounts, but nobody has reviewed them yet. -1, -5, etc. Based on the date of the pull. No — since there is no deadline for account reviews, this notification should not be enabled by default.

Comments & Attachments

Name Recipients Conditions Variations Enabled
New Comment & Attachment GRC Contact, Reviewer New Comment & Attachment No

Explicit visual differentiation for reviews

We should introduce colors on the view column to clearly differentiate review-related changes.
Adding colors to the view is very hard and will take a lot of time. Then we will handle it with simply plus-minus, for example: +SUPPORT -CONSULTING

Edit Modal

Account reviews will be done on this section, and they will be done through the edit button.

Field Mandatory Information
Account NA This field will have the Name of the account found, Issue and Roles displayed together like the picture below.
Review Yes Reviewed/Not Reviewed (remove not sure)
Comment No
Create Finding No Button to create finding on this. On this create finding, you will need to set the deadline date and the title because the other information already comes from the account review.

You will only be able to select a decision: Reviewed / Not Reviewed. “Not sure” will be deleted.

Bulk actions should also be supported to apply Reviewed / Not Reviewed decisions across multiple rows using bulk edits. When creating a finding on bulk edit, there will be only 1 finding assigned to the accounts selected, so the relationship is one to many.

Findings

Finding will be open by default, and once closed, you need to put the date, and you won’t be able to edit it anymore. Very very similar behavior as compliance exceptions.

Form

It will have only one tab.

Field Mandatory Hidden Notes
Name Yes
Description No Yes
GRC Contact Yes No
Reviewer Contact Yes No
Status Yes* No *It will be “Open” by default and disabled.
Expiration Date Yes No Previously named “Deadline”, rename it to "Expiration Date "
Account Review Pull Yes No This will show the list of pulls in the following format: Account Review Name , Pulled Date (add HH:MM:SS), Latest (this will only be displayed if it is the latest pull), hash
Accounts Yes No

Default View

Field Information
Dynamic Status
Name Name of the finding
Status Open/Closed
GRC Contact
Reviewer Contact
Start Date The date the finding was created
Expiration Date Expiration date set on finding creation
Closure Date The date the finding status was changed to “Close”
Account Review Account review name associated
Accounts Accounts Name (ex. adrian.santa) it can be more than one.

Pinned Views

View Filter
All Items All findings
Open Findings Open status = true.
Closed Findings Close status = true.
Expired Findings Expiration date has passed.
Findings Expiring In 30 Days Status is not Closed and Expiration Date Before Actual Date 30

Not Pinned Views

View Filter
Findings Expiring In 14 Days Status is not Closed and Expiration Date Before Actual Date 14

Dynamic Status

Name Description Variations Enabled
Open Findings Open status = true. Yes
Closed Findings Close status = true. Yes
Expired Findings Status is not Closed and Expiration Date Before Actual Date Yes

Notifications

Report

Name Recipients Description Variations Enabled
Open Findings Report Admin Open Findings No
Closed Findings Report Admin Closed Findings No
Expired Findings Report Admin Expired Findings No

Warning

Name Recipients Conditions Variations Enabled
Item Created GRC Contact, Reviewer New item created. No
Item Edited GRC Contact, Reviewer Item has been added. No
Item Deleted GRC Contact, Reviewer Item has been deleted. No
Finding Due in x Day GRC Contact, Reviewer 1 / 10 / 30 days No
Expired Finding GRC Contact, Reviewer

Comments & Attachments

Name Recipients Conditions Variations Enabled
New Comment & Attachment GRC Contact, Reviewer New Comment & Attachment No

Migration Considerations

  • The feedback that is currently marked as “Not Sure” will count as items Not Reviewed, They will be displayed on the accounts review column of “missing review”.
  • The portal button on the top right side will be removed.
  • All the notification macros And any reference to the portal. should now redirect to the feedback tab instead of the portal.

Not Contemplated (WILL NOT BE DEVELOP NOW)

Feed based on SCIM user synchronization

This would reduce CSV/API/automation scripting and make Eramba easier to connect with Entra ID, Okta, Google Workspace, etc. Use that as a current list of employees, for example.

Onboarding wizard:

  • Create a helper wizard that appears the first time a user creates an account review. The wizard would guide the user through creating a feed, testing it, creating the account review, configuring notifications, and triggering the first pull.

  • This would make the feature much easier to understand, as its current usage is relatively low.

Option 1: Simple where to click options

Option 2: Guidance with an actual form and more in-depth steps and descriptions

Outbound provisioning / deprovisioning

Add the ability to automatically deprovision “Not OK” accounts.

This could probably be implemented using automations.

Templates

Account reviews are highly company-dependent, so templates are not really applicable.

AI recommendations

For AI to provide meaningful recommendations during an account review, it would require a significant amount of context about the organization, employees, departments, and internal processes. Because of that, it is very difficult to make reliable recommendations in a generic way.