Legal & Compliance
Transparency is the foundation of trust. Review our legal documents, data processing agreements, and compliance commitments.
Access Review AI Recommendations
Risk Classification Rationale
This AI system recommends approve/revoke/flag decisions for identity access reviews, directly affecting employee and contractor access rights to essential work systems.
EU AI Act: Category 4(a) — Employment, workers management, access to self-employment
Purpose
Generate non-binding access review recommendations to assist human reviewers in identity governance campaigns. Analyzes peer group prevalence, entitlement risk levels, segregation of duties conflicts, and dormancy.
Input Data
- —Identity entitlements and assignments
- —Identity profiles (department, role)
- —Access review item metadata
- —Entitlement risk levels
- —Segregation of Duties violation flags
- —Peer group prevalence statistics
Output Data
- —Recommendation per item: approve, revoke, or flag for review
- —Confidence score (0-100%)
- —Natural language rationale
Model & Processing
Known Limitations
- !Cannot assess business context for legitimate exceptions
- !Peer group analysis depends on accurate department/role data
- !Confidence scores are not calibrated probabilities
- !Small peer groups (<5 members) produce unreliable statistics
Fairness Measures
- +Monthly automated bias audits measuring demographic parity and disparate impact ratio
- +Override rate monitoring by department and role group
- +Minimum cohort size (5 profiles) for peer group analysis
- +Action threshold: >10% deviation triggers investigation
Human Oversight
Human reviewer must explicitly approve or reject each access review item. AI recommendation is non-binding and displayed alongside raw entitlement data. Overrides require documented reason and are logged for audit.
Appeal Process
Any person affected by an AI-assisted access decision may request human-only review via the Appeal button. Appeals are assigned to the compliance team and resolved within 14 days. The reviewer reassesses without AI recommendation visible.
Data Governance
Recommendations cached for 90 days after access review completion, then purged. No customer data used for model training. All processing in France (EU). Tenant-isolated via row-level security.
AI System Card · EU AI Act (Regulation (EU) 2024/1689) · Articles 11, 13 · Last updated: March 2026