Access Control Reviews
Access Control Reviews are included in Premium and Enterprise, and they work
during the demo too.
Knowing who can reach an AI system — its prompts, its data, its configuration and its outputs — and confirming that access is still appropriate is a routine governance control. An access control review captures one such review — who was looked at, and what you decided for each person.
Starting a review
Create a review with a title, an optional AI system it covers (or leave it as a general review), a period label (e.g. "Q1 2026"), an optional due date, and notes. When you create it, every active team member is added as a row to review, each starting as pending.
Working through it
For each person, record their access level and a decision — keep, remove, or modify — with optional notes. Save as you go. You can also set a decision on several rows at once. The review moves Open → In Review → Completed; once you complete it, the rows lock so the record is a faithful snapshot of what you decided and when.
Due dates
If you set a due date and the review isn't complete by then, it's flagged overdue in the list, and once a week an overdue review also notifies your org admins so it doesn't sit unnoticed. That reminder rides your ordinary "remediation overdue" notification preference, so you can turn it off.
Reviews are still created manually — the period label is for your own cadence (quarterly, annually); there's no automatic recurrence.
Who can do what
Org admins create reviews, record decisions, and complete or delete them. Everyone else can view completed reviews read-only.