Manage → Organisation → Access is where you track which software systems your company uses, who has an account on each, and periodically review that access is still appropriate.
Systems
Systems are added automatically by connected integrations (Okta, Google Workspace, AWS, GitHub, etc.), or you can Add System manually for anything not integrated. Each system's Reviews status shows whether it's ever been reviewed.
Accounts
Click into a system to see its accounts:
In Scope accounts count toward reviews and compliance tests; Excluded ones don't.
Integration-synced accounts are read-only here — manage them at the source system. Add Account manually only applies to systems without a live integration.
Running a review
From the Access Reviews tab, Start New Review walks through every in-scope account so you can mark each as still-appropriate or not.
Important: rejecting an account in a review does not revoke that person's access. ComplyJet can't act on the source system on your behalf — a rejected account is just a flag for you. You still have to go remove that person's access in the actual tool (Okta, AWS, GitHub, etc.) yourself.
Keeping reviews current
A system needs a completed review within the last 365 days to satisfy the underlying compliance test — reviews effectively need re-running annually, even if nothing about the system has changed.



