Why run an access review campaign?
Access review campaigns help Security and IT teams to securely control what software users can access, all while making sure employees can also successfully complete their work. From a least privilege and security perspective, ensuring that users only have the access they need, for only as long as they need it, reduces the access footprint of your company for sensitive systems and data. Running regular access review campaigns also helps you to achieve compliance with security standards and audit requirements.View all campaigns
On the Campaigns page, campaigns are sorted by state and type:
- Running campaigns are currently in progress.
- Draft campaigns have not yet started.
- Completed campaigns have ended.
- Templates are saved campaign outlines used to create one-time or recurring scheduled campaigns.
How do campaign templates work?
If there’s a campaign pattern you use repeatedly, create a reusable campaign template instead of configuring the same campaign from scratch every time.
Create a new campaign
Follow this process to create a single campaign. Jump to Create a campaign template to set up a template that can be used to create many similar campaigns.Step 1: Set up the campaign
1
Navigate to Admin > Campaigns.
2
Click New campaign.
3
Fill out the form, providing the following information:
- Name: The campaign’s name, which will be displayed to reviewers and shown in the campaign list view.
- Description: The description of what this campaign entails and any directions you want to deliver to reviewers.
- Campaign type: Select Single instance, then set the Target completion date for the campaign.
- Owner: The campaign’s owner, who will manage the campaign while it is in progress. You can set more than one campaign owner. Each owner must have the Campaign Administrator or Super Administrator user role in ConductorOne.
- Review policy: The campaign’s default review policy. If needed, you’ll be able to adjust the policy to be used for the review of individual entitlements later in the campaign creation process.
4
Click Continue. The campaign is created.
5
On the Configuration tab, review and update the details you’ve entered so far.
6
If you want to provide any instructions to reviewers about how to complete access reviews in this campaign, click Edit and enter the instructions in the Review instructions field.The instructions you enter will be displayed to all reviewers at the top of the page where they complete their access reviews. You can format your instructions using Markdown to add emphasis, links, and structure.
7
If you want all reviewers to receive their campaign tasks in the same format, select a Default access review view:
- By application: review access to one application at a time
- By user: review one user’s access at a time
- Unstructured: all the assigned reviews together in one list
8
By default, all campaign tasks will be created using the review policy you chose. If instead you want campaign tasks to use the review policies set on the entitlements or apps in the campaign, click Edit and click to turn on Use preferred review policies.If this option is enabled, ConductorOne will apply policies using this order of precedence: entitlement, application, campaign.
9
In the Campaign completion section, you can configure what actions the campaign will automatically take when it ends:
- Notify all campaign owners
- Generate a campaign report and notify all campaign owners when it’s ready for download
10
If you want to use a Slack channel for communication about this campaign, click Add Slack channel. Enter a Slack channel name, either an existing channel in your workspace or the name for a new channel you want to create.All campaign owners and users assigned access reviews will be automatically added to this channel when the campaign starts.
Step 2: Choose what to review
Next, build a list of the resources that your campaign will review.1
On the Scope tab of your campaign, find the Apps and resources section of the page and click Make selections.
- To run a UAR on user access to specific permissions, click Review specific resources and select resources, then click Save. OR
- To run a UAR on user access to applications, click Review application access and select apps, then click Save. OR
- To run a UAR on all of the resources of a given resource type within a specific app (such as all the groups within Google Workspace), click Review resources by type and select the resource types for each applicable application, then click Save.
2
If you’re building a UAR reviewing specific resources, click Edit scope to remove entitlements from the review or update the policy used to review specific entitlements. Click Apply changes when you’re finished.

3
Optional. Find the User selection section of the page and click Make selections.If you don’t make any selections here, all users with access to the apps or resources you selected above will be added to the campaign. If you want to narrow the focus of the UAR:
- Click Select specific users to build a list of users whose access will be reviewed, then click Save. OR
-
Click Select users by criteria to review users who match the criteria you set, then click Save.
You can mix and match these options:
- User status in ConductorOne
- Direct reports of a manager
- User profile attributes. For example, to run an access review campaign on all the AcmeApp users in your company with the job title “Engineer”, create the parameter User AcmeJob is Engineer.
- Exclude users in specific groups from the campaign
- Click CEL expression to enter a CEL expression that describes the users you want to review. The expression must return a list of users to be valid.
4
Optional. Find the Account parameters section of the page and click Make selections.If you don’t make any selections here, all accounts with access to the apps or resources you selected above will be added to the campaign. If you want to narrow the focus of the UAR:
-
Click Select accounts by criteria to review app accounts that match the criteria you set, then click Save.
You can mix and match these options:
- No account owner
- Account status
- Account type
- Account domain (specifically, whether the email address associated with the account has been marked trusted by a C1 admin at your organization)
- Click CEL expression to enter a CEL expression that describes the accounts you want to review. The expression must return a list of accounts to be valid.
5
Optional. Find the Grant parameters section of the page and click Make selections.If you don’t make any selections here, all access grants of the apps or resources you selected above will be added to the campaign. If you want to narrow the focus of the UAR:
-
Click Select grants by criteria to review only the access grants that match the criteria you set, then click Save.
You can mix and match these options:
- New grants added within the time period you select or between two specific dates
- Temporary (time-limited) or permanent grants
- Grants that have not been used in the time period you select (this information is not available for all applications)
- Direct grants (permissions assigned directly to users) or inherited grants (permissions assigned to a group or role, which are “inherited” by users assigned to that group or role)
- Grants sourced from access profiles (check the box to exclude these grants from your campaign)
Step 3: Check data accuracy
If any of your selections are sourced from connectors or file uploads that have not been updated recently, you’ll see an indicator and a Your campaign might have data accuracy issues banner on the Accuracy tab.
- A connector hasn’t synced for more than two days
- A file source hasn’t been updated in more than seven days
- A connector errored during the most recent sync
Step 4: Prepare the campaign
1
When you’re ready, click Prepare campaign. Preparing a campaign generates the individual access review tasks, but does not launch the campaign. Please be patient: depending on the size of the campaign, preparing it might take several minutes.
2
Review the draft campaign’s details. If necessary, you can make changes on the Configuration tab, but you cannot alter the campaign’s scope or policy once it has been prepared.
Step 5: Start the campaign
1
When you’re ready, click Start campaign. Select whether ConductorOne should email campaign kickoff notifications to the users who are assigned the access reviews in the campaign.
2
Click Start campaign. Again, depending on the size of the campaign, starting it might take several minutes.
Duplicate a past campaign
Instead of creating a campaign from scratch, you can save time and effort by duplicating a past campaign and tailoring it to your current needs.1
Navigate to Admin > Campaigns.
2
Locate and click on the name of the campaign that you want to duplicate.
3
From the more actions (…) menu, select Duplicate.
4
Review the campaign’s details and update the information as necessary.
5
Follow the instructions above to validate, prepare, and start the duplicate campaign.
Create a campaign template
Step 1: Set up the template
1
Navigate to Admin > Campaigns.
2
Click New campaign.
3
Fill out the form, providing the following information:
- Name: The campaign’s name, which will be displayed to reviewers and shown in the campaign list view.
- Description: The description of what this campaign entails and any directions you want to deliver to reviewers.
- Campaign type: Select Template, then set the Campaign duration, or how long each campaign created from the template will run.
- Owner: The campaign’s owner, who will manage the campaign while it is in progress. You can set more than one campaign owner, just be sure anyone you add has the Campaign Administrator or Super Administrator user role in ConductorOne.
- Review policy: The campaign’s default review policy. If needed, you’ll be able to adjust the policy to be used for the review of individual entitlements later in the campaign creation process.
4
Click Continue. The template is created.
5
On the new template’s Configuration tab, in the Campaign completion section, you can configure what actions campaigns created from this template will automatically take when they end:
- Notify all campaign owners
- Generate a campaign report and notify all campaign owners when it’s ready for download
6
Optional. If you’d like to use a Slack channel for communication about the campaigns created by this template, click Add Slack channel. Enter a Slack channel name, either an existing channel in your workspace or the name for a new channel you want to create.When a new campaign made from this template starts, all campaign owners and users assigned access reviews will be automatically added to this channel.When new campaign instances are created from this template, you’ll have a chance to change the Slack channel before starting the campaign.
Step 2: Choose what to review
Next, build a list of the resources that campaigns made from this template will review.1
On the Scope tab of your template, find the Apps and resources section of the page and click Make selections.
- To run a UAR on user access to specific permissions, click Review specific resources and select resources, then click Save.
- To run a UAR on user access to applications, click Review application access and select apps, then click Save.
- To run a UAR on all of the resources of a given resource type within a specific app (such as all the groups within Google Workspace), click Review resources by type and select the resource types for each applicable application, then click Save.
2
If you’re building a UAR reviewing specific resources, click Edit scope to remove entitlements from the review or update the policy used to review specific entitlements. Click Apply changes when you’re finished.

3
If you’re building a UAR reviewing specific resources, click Edit scope to remove entitlements from the review or update the policy used to review specific entitlements. Click Apply changes when you’re finished.

4
Optional. Find the User selection section of the page and click Make selections.If you don’t make any selections here, all users with access to the apps or resources you selected above will be added to the campaign. If you want to narrow the focus of the UAR:
- Click Select specific users to build a list of users whose access will be reviewed, then click Save.
-
Click Select users by criteria to review users who match the criteria you set, then click Save.
You can mix and match these options:
- User status in ConductorOne
- Direct reports of a manager
- User profile attributes. For example, to run an access review campaign on all the AcmeApp users in your company with the job title “Engineer”, create the parameter User AcmeJob is Engineer.
5
Optional. Find the Account parameters section of the page and click Make selections.If you don’t make any selections here, all accounts with access to the apps or resources you selected above will be added to the campaign. If you want to narrow the focus of the UAR:
-
Click Select accounts by criteria to review app accounts that match the criteria you set, then click Save.
You can mix and match these options:
- No account owner
- Account status
- Account type
- Account domain (specifically, whether the email address associated with the account has been marked trusted by a C1 admin at your organization)
6
Optional. Find the Grant parameters section of the page and click Make selections.If you don’t make any selections here, all access grants of the apps or resources you selected above will be added to the campaign. If you want to narrow the focus of the UAR:
-
Click Select grants by criteria to review only the access grants that match the criteria you set, then click Save.
You can mix and match these options:
- New grants added within the time period you select or between two specific dates
- Temporary (time-limited) or permanent grants
- Grants that have not been used in the time period you select (this information is not available for all applications)
- Direct grants (permissions assigned directly to users) or inherited grants (permissions assigned to a group or role, which are “inherited” by users assigned to that group or role)
- Grants sourced from access profiles (check the box to exclude these grants from your campaign)
Step 3: Schedule upcoming or recurring campaigns
You can set the template to create instances of the campaign on a date in the future or on a recurring schedule. You can also create an on-demand instance of the campaign at any time.1
Return to the Configuration tab.
2
If you want to provide any instructions to reviewers about how to complete access reviews in campaigns created from this template, go to the Details area of the page and click Edit, then enter the instructions in the Review instructions field.The instructions you enter will be displayed to all reviewers at the top of the page where they complete their access reviews. You can format your instructions using Markdown to add emphasis, links, and structure.
3
If you want all reviewers to receive their campaign tasks in the same format, select a Default access review view:
- By application: review access to one application at a time
- By user: review one user’s access at a time
- Unstructured: all the assigned reviews together in one list
4
By default, all tasks in campaigns created from this template will be created using the review policy you chose. If instead you want campaign tasks to use the review policies set on the entitlements or apps in the campaign, click Edit and click to turn on Use preferred review policies.If this option is enabled, ConductorOne will apply policies using this order of precedence: entitlement, application, campaign.
5
Optional. If you’d like to automatically create draft instances of this campaign, either once on a date in the future or regularly on a set schedule, go to the Schedule area of the page and click Edit.
1
Click to turn on Schedule.
2
Choose the date you want a draft instance of this campaign to be created.
3
Using the Frequency selector, choose a frequency option to automatically create recurring instances of the campaign, beginning on the date you chose and recurring at the frequency you set.Choose None if you only want to create a single scheduled instance of the campaign on the date you chose.
4
Click Save.
Step 4: Review and start a campaign created from a template
When a new campaign is created from the template, it is shown on the template’s Campaigns tab and also added to the Drafts tab. Edit the campaign as needed, then follow Steps 3 through 5 in Create a new campaign to review current data accuracy, prepare the campaign, and start the campaign.Frequently asked questions about creating campaigns
What happens if I add an empty entitlement to the campaign?
What happens if I add an empty entitlement to the campaign?
In short, nothing. If you select a resource for your campaign that does not have any grants on any of its entitlements, no review tasks will be created for the resource, as there is nothing to review. You can add these resources to your campaign without impact, or leave them out: it’s up to you.
Can I add or edit campaign instructions once the campaign is underway?
Can I add or edit campaign instructions once the campaign is underway?
Yes, you can! Go to the running campaign’s Configuration tab and add or edit the campaign instructions. Reviewers will see the new version of the instructions as soon as you click Save.