DISCOVER · REVIEW · REMEDIATE
FAQ

Frequently asked questions.

Certification, evidence, RITA, INSIGHTS, editions, deployment and security. If your question is not here, ask it in a demo request.

Certification

What is REVIEWIT?

REVIEWIT is an access certification platform. It runs campaigns in which named humans certify access, ownership and authority over resources across your digital estate, and it preserves tamper-evident proof of every decision. It is not an identity governance suite: it does no provisioning, no lifecycle, no role model.

How is that different from an identity governance suite?

A suite manages the lifecycle of identities and their entitlements. REVIEWIT certifies decisions about them and proves those decisions were made by people. The two are complementary. Where a suite tells you a review happened, REVIEWIT tells you who decided what, seals it, and next time tells you whether the same access came back.

Which policies are available?

Ownership, membership, orphan, inactivity, overshared, external sharing, guest lifecycle, privacy, privileged access, role definition and data lifecycle, plus custom policies. Each policy is a campaign extension with its own settings.

Can business teams run their own campaigns?

Yes. A workspace is a unit of delegated governance with boundaries, features and a credit envelope set by the subscription administrator. Workspace managers design and run campaigns within those boundaries.

Does REVIEWIT apply the revocations?

No. REVIEWIT decides and certifies; it does not execute in your systems. A revocation is a certified decision you apply in your own tooling. INSIGHTS will tell you in the next campaign whether it took effect.

Evidence

What does sealed evidence mean?

Every closed campaign occurrence and every audit trail segment is sealed by SEAL, a dedicated sealing authority backed by a vault. The application hosts cannot seal anything themselves. The result is tamper-evident evidence chained per scope.

Who signs off a campaign?

A named human, always. The platform never signs and cannot be configured with a delegated signer. Sign-off is aggregated per request batch and recorded in the audit trail.

What can an auditor see?

Auditor access is read-only and limited to evidence: the sealed segments, the certification dossier, the decisions and their sign-off. Auditors do not see INSIGHTS, which is your own analysis, and they cannot decide anything.

How long is evidence retained?

According to a retention module that declares every data category with its period and purge behaviour, matching the DPA clause in your contract. Legal holds suspend purge for a scope. Audit trail purge removes whole sealed segments, never individual rows.

RITA and INSIGHTS

What is RITA?

RITA, the ReviewIT Trusted Assistant, is the assistant built into every console. It explains context, definitions and screens in the reviewer's language. Its response contracts contain no decision action, so it cannot approve, revoke or sign, and every turn is written to the audit trail with the tools it actually invoked.

Can RITA make decisions if we configure it to?

No. There is no decision type in its contracts to enable. This is an architectural property, not a setting.

What is INSIGHTS?

INSIGHTS compares closed campaign occurrences that share the same configuration: what changed between two terms, what came back after a revocation, and findings on effort, delays and reviewer concentration. It complements reports: reports prove the review happened, INSIGHTS tells you whether it worked.

Is INSIGHTS available in OneShot?

No. INSIGHTS is part of the Unlimited edition. OneShot shows a showcase of what it would say once your estate has comparable occurrences.

Editions and deployment

What are the editions?

OneShot consumes credits per decision, per campaign, for a deadline or a first certification. Unlimited is tiered by governed identities with unlimited campaigns and decisions across the term, and includes INSIGHTS. Every capability, policy and connector is in both.

How are credits bought?

By card through the Subscription Manager, or by invoice. Credits come in lots that expire after two years and are consumed first-in first-out. The platform holds no card data.

Can REVIEWIT be deployed on-premise?

Yes. The same consoles, jobs, vault and sealing authority can be deployed inside your infrastructure. The managed service runs on a regional foundation with authentication and sealing authorities per region.

Which identity providers are supported?

Entra ID, Google and generic OpenID Connect providers through TrustGate, REVIEWIT's identity broker, with MFA step-up enforced on administrative surfaces and a setup guide per provider.

Security

Does REVIEWIT support BYOK?

Yes. You can bring your own key for your subscription's data. Encryption at rest and in transit, tenant isolation and a regional foundation are part of the platform.

Where do secrets live?

In a vault, never in configuration files. Customer keys, the assistant's call secret and the platform's own caller identities are held there and rotated by jobs.

Can we stream events to our SIEM?

Yes, through BEACON: audit events streamed to your destinations with one lease per destination, egress protection and delivery proofs kept as evidence.

Is there an API?

Yes, for campaign automation and outcome reading, with scoped credentials and quotas. Review decisions are never exposed to the API, so no script can decide.

Still a question?

Ask it in a demo request. We answer within one business day.