Access Review

Periodic access control on your workspace

A workspace category may have a periodic Access Review set up (see Workspace category Access Review setting).
As the owner of a workspace within such a category, you will be periodically requested to perform an Access Review for your workspace.

A few days prior to the Access Review due date, PortalTalk sends an email to the owners of the relevant workspace.
If the review has not been completed on the Access Review due date, PortalTalk will send a reminder email to the owners that day and an email to the PortalTalk security officer.

If the owners still fail to perform the Access Review, PortalTalk will begin sending reminder emails to workspace owners. It will keep repeating this until the user has completed all open Access Reviews.

In the Access Review you verify three security aspects:

  • Whether all current team members still require access to the workspace.

  • Whether the roles/permissions currently assigned to the individual team members are still required.

  • Whether any information shared with users outside the team is indeed being shared by necessity.

The category's Access Review settings determine which of the three parts of the Access Review must be performed for your workspace (see Workspace category Access Review setting).

The following topics are explained on this page:

  • The Access Review notification.

  • Performing the Access Review.

The periodic Access Review notification

Periodically, the Access Review request is made to you as a workspace owner by means of an automated email message.

image-20220615-121637.png

The text of these automatically generated email messages can be set/modified by the PortalTalk application administrator.
See the manual page related to managing the PortalTalk email templates.


Perform the Access Review

  • Click the link in the notification email message.

Part 1 Review the team composition of the workspace

The PortalTalk application is launched in a new browser tab, with the page Invited users* displayed:

image-20220615-124328.png

 

The page Invited users for <workspace name>*​ lists all team members within your workspace with the date the user was added to the team, the user type (Owner, Internal or External team member) and the date the user was last logged in to PortalTalk 365. The external team members are displayed at the top of this list.
*This page will only be presented if it is determined within the category settings that the team composition must be reviewed.

  • Verify if all listed users still require access your workspace.

  • Select the Remove option for the team members who no longer require access to your workspace.

  • Click the button Next at the bottom right of the page.

Part 2 Review the team members' permissions

The page Revoke permissions for members* is presented:

image-20220615-124618.png


The Revoke permissions for members* page lists, per remaining team member, all assigned permissions.

*This page will only be presented if it is determined within the category settings that the role assignments must be reviewed.


  • Select, in the Revoke column, the permissions that the concerned team members no longer need to use.

  • Click the button Next at the bottom right of the page.


Part 3 Review the shared documents

The page Undo document sharing* is presented:

image-20220615-124833.png

 The Undo document sharing* page lists all documents in your workspace's SharePoint site which are shared with users outside of the workspace team, including all individual items with unique permissions.
*This page will only be presented if it is determined within the category settings that the shared documents must be reviewed.

  • In the Undo column, select the items you want to reset to their original permissions.

  • Click the button Next at the bottom right of the page.


Part 4 Confirm the privacy setting of the workspace

The Privacy Setting page* is presented:

image-20240312-114312.png

The Privacy Setting page* draws your attention to the current privacy setting of your workspace.
Working in an MS Teams environment should probably reflect the modern way of collaboration, where every user in the organization has as much access to information as possible. Although some information should only be accessible to team members, private workspaces should remain an exception.

*This page will only be presented if your workspace's category settings specify that this part of the Access Review has to be performed.

  • In the Should this still be allowed? section, adjust the privacy setting of your workspace if so required.

  • Click Next at the bottom right of the page.


Part 5 Confirm and apply your choices

The Access Review Summary page is presented:

image-20220615-125031.png


 On the page Access Review Summary you can review the choices you made on the previous Access Review pages.

  • If necessary, go back to previous pages to adjust your choices.

  • At the bottom right of the page Access Review Summary, click Apply to apply your chosen actions and to complete the Access Review wizard.

The periodical Access Review is now completed.