To start a user review, you must have the Opal Auditor role.In the Inventory tab, select the App Opal. Here you’ll find the Opal Auditor role.If you’re an Opal Admin, you can add yourself directly to the resource by navigating to the User Access tab and clicking on the + Add Users. If you’re not an Opal Admin, you can request access to the role.
You can create recurring reviews from the Schedules tab, specifying months and . Select + Create Schedule and specify the months and day of the week to run the review. You can edit the review—its groups, users, resources, etc.—at any time, and changes take effect on the next scheduled review.
In the Users and Entities sections, you can filter specific users and entities (resources, nonhuman identities, groups, and apps) to review. See the preview next to the Cancel and Create buttons—e.g., 171 resources, 60 groups, 18 apps in the below screenshot—to see affected entities as you update filters.Consider the following filters when you select what to review:
Filter by user: Include only resources and groups that certain users have access to in the review. The user filter is applied first before any other filters are applied to entities.
Filter by specific entities: Select specific resources, nonhuman identities, groups, and apps to include in the review. Note that the entity filter only includes the entity itself. For example, if you specify a resource and want to review the groups who can access the resource, you must add the groups as entities as well.
Filter by apps: Specify resources and groups to include from certain apps.
Filter by admin: Include resources and groups owned by specified admins.
Filter by resource and group type: Include resources and groups of certain types.
Filter by tags: Include resources and groups with certain tags.
Filter by name: Include resources and groups whose names match a given substring.
If you use linked groups and would like to include users from source groups in the access review, consider toggling on Include linked group source groups.