- Help centre
- Access and security
Task guide
Reviewing who has access
Review the firm's dated grant snapshots, confirm or remove each one, then sign off and export the retained record.
Each period's review
The daily job opens a review for each department head covering that department's open members. The managing partner covers people outside a department and departments without an active head. A head of several departments receives one review for the period.
The default period is three months, with 21 days to finish from opening. The firm changes these values under Settings, General, Security. An overdue review tells the managing partner once.
Open Settings, Access reviews, or follow the review notification. Assigned reviewers act on their own reviews; access managers can read and manage every review. Search by reviewer, period or standing to find an earlier signed-off record.

Decide every line
A review is a dated snapshot of each person's roles, permission overrides and temporary matter access. Search and filters read the server's pages, rather than narrowing only the rows on screen.
- Open the review and read the grants grouped under each person.
- Choose Confirm for access that should remain. Confirm all confirms every undecided line for that person, including lines on later pages.
- Choose Remove for access that should end, give the reason and confirm the consequence. The decision and who took it are retained.
- Open a line to read its whole grant label, dates, decision, reason and decider.

Removing a live role requires the existing two-person permission change workflow first. A live permission denial also stays in the override approval workflow. The refusal links to the person and role and shows the way to Permission requests. Already ended or replaced grants can be marked removed without ending them again.
Sign off and keep the evidence
Choose Close review once every line has a decision. A refusal tells you how many remain undecided. Confirming close signs off the record; its decisions then cannot change.
A closed review offers Export to people who may export records. Choose PDF for the signed-off auditor record, or CSV for every decision as rows. The export includes reviewer, period, grants, decisions, reasons and times, and is itself audited. A wall preventing you from reading a reviewed grant also prevents a complete export.
Was this helpful?
Read next
- Asking for accessAsk for one permission or one matter for a fixed period, follow the decision and end access when you no longer need it.
- Roles, permissions and scopesWhat a person may do is decided by the permissions their roles grant, each at a scope, never by the name of their role.
- Change what a person may doInvite a person, give them roles, add or take away a single permission for them, and deactivate them when they leave.
- Ethical wallsA wall makes a matter or a client invisible to the people it shuts out, everywhere in the system, until two people agree to lift it.
- The audit trailEvery change, and every view of confidential material, is written down with who, what and when, in a record no one can edit.
