Why Access Tests
In addition to manual access reviews, most compliance frameworks — including SOC 2 and ISO 27001 — require that your access configurations follow secure best practices.
Things like rotating access keys, enforcing MFA, and controlling admin privileges are essential to reducing the risk of unauthorized access. ComplyJet helps automate this by running a series of access configuration tests across your integrated systems.
What These Tests Do
Once you've integrated tools like AWS, Google Workspace, GitHub, and others, ComplyJet automatically starts running tests against their access settings.
For example:
Is MFA enabled for all admins?
Are AWS IAM access keys rotated regularly?
Are there unused service accounts with active credentials?
Each test is mapped to specific controls from the frameworks you selected — helping you generate real, audit-ready evidence as you secure your systems.
Access Tests Page
Go to Manage → Organisation → Access, then the Tests tab (the Systems tab next to it is a separate feature — that's where you run access reviews, not automated tests).
Tests are filterable by All / Passing / Failing / Excluded, with Export and Re-run all tests actions at the top:
Each row shows the test name and description, which provider it checks (AWS, GitHub, GCP, Bitbucket, Cloudflare, and others), current Run Status, and which Frameworks it maps to.
If a test is failing, click into it to view more details.
Fixing Failing Tests
Clicking into a test opens the same detail view used across ComplyJet's tests — Evidence, Remediation, Details, and Controls tabs:
Evidence lists the specific accounts or resources that failed and why — for example, an access account still assigned to someone who's no longer a current employee or contractor. Remediation gives numbered, step-by-step instructions for the affected system:
For example, if a test flags that GCP access accounts doesn't have MFA enabled, it’ll tell you which accounts are affected and provide exact instructions to enable MFA for these.
Once you've applied the fix, click Trigger Run to re-run that test directly from the page — or use Re-run all tests from the main Tests list to refresh everything at once. If everything checks out, the status will change to Passing — and that’s one more compliance item complete.
Final Goal
Your objective is to ensure:
Every test is passing
Misconfigurations are fixed promptly
Access settings across systems stay secure and aligned with compliance requirements
These automated tests give you continuous visibility into access-related risks — without waiting for a manual review or audit to catch them.




