How Reviewer Assignments Work in Zluri

Zluri’s Access Reviews module supports flexible reviewer assignment logic to ensure that all user records within a certification are reviewed by the right person—automatically, reliably, and with minimal manual intervention.

Reviewer Types in Zluri

When configuring reviewers for an entity (e.g., application or group) within a certification, Zluri provides two assignment options:

1. Primary Reviewer

The Primary Reviewer is the main person responsible for taking review actions (approve, modify, revoke) for each assigned record. This is configured during certification setup.

You can assign a Primary Reviewer using:

Role-Based Assignment

Choose from:

  • Reporting Manager – Pulled from the identity source (e.g., your IDP or HRIS) configured in Zluri under Directory Management.
  • Department Head
  • Application-specific roles (if you're reviewing apps):
    • App Owner
    • App IT Owner
    • App Finance Owner

These roles can be centrally managed and maintained in Zluri.

User-Based Assignment

Manually assign a specific user (e.g., [email protected]) as the reviewer for all relevant records.

2. Fallback Reviewer

The Fallback Reviewer acts as a failsafe and is triggered when the Primary Reviewer is unavailable, unassigned, or inactive for a given record.

When is the Fallback Reviewer used?

  • If the role-based primary reviewer (e.g., Reporting Manager) is not populated for a user in your HRIS or IDP.
  • If the assigned reviewer is a named user and is no longer active in the org when the certification starts.

Example 1:

Primary Reviewer = Reporting Manager

For user Alice, no reporting manager is defined in the source of truth.

➝ Fallback Reviewer gets assigned.

Example 2:

Primary Reviewer = John Doe

Certification is scheduled to start 30 days later. John leaves the company before it starts.

➝ Fallback Reviewer automatically steps in at launch time.

Note: Fallback Reviewer must always be a specific named user, not a role.

Who Takes Action?

Although Primary and Fallback reviewers are both configured during setup, only one reviewer per record is ultimately responsible.

Once the certification is created, Zluri automatically determines the Current Reviewer for each record based on the Primary and Fallback logic. The Current Reviewer column in the UI reflects this assignment.

Only the Current Reviewer has permission to take action on the record.