How Self-Review Configurations Work in Zluri
During access certification setup, it’s possible that a user might get assigned to review their own access. Zluri provides flexible self-review configuration options to handle such scenarios in line with your organization’s policies.
When Does Self-Review Occur?
Self-review scenarios can arise when the same user is both the reviewer and the subject of the review. This can happen due to role-based or user-based assignments.
Common examples:
- An App Owner is assigned to review an application they own and have access to
- A Department Head is assigned to review group memberships while also being a member of that group
- A user is assigned to review access to an application they use
Self-Review Configuration Options
While creating a certification, Zluri allows admins to define how self-review scenarios are handled. Two options are available:
Allow Self-Review
Choose this option if your organization’s policies permit users to review their own access.
- No reassignment is triggered.
- The user can approve, modify, or revoke their own access during the review.
Auto Reassign
Select this option if your organization’s policies do not allow self-review.
Zluri will automatically reassign the review task based on your selected fallback path. You can choose to reassign to:
a. Role
Choose from available roles such as:
- Reporting Manager
- Department Head
- App Owner, App IT Owner, App Finance Owner (if applications are being reviewed)
- Fallback Reviewer
- Certification Owner
b. User
Manually select a named user who should handle all self-review reassignment cases.
Reassignment
When Auto Reassign is selected, Zluri follows a layered fallback logic to ensure every record has a valid reviewer:
- Primary Reviewer Check
- Zluri first checks if the primary reviewer (role/user) is active and assigned.
- Fallback Reviewer Check
- If the primary reviewer is not available, Zluri checks for a fallback reviewer.
- Self-Review Conflict Check
- If the reviewer assigned through either the primary or fallback configuration is the same user as the one being reviewed, Zluri checks for the configured reassignment role or user.
- Auto-Reassignment Execution
- Zluri checks if the auto-reassign target (role or user) is valid and active.
- If valid, the review is reassigned accordingly.
- Final Fallback: Certification Owner
- If no reassignment target is resolvable (e.g., role unconfigured or user deactivated), Zluri assigns the record to the Certification Owner.
Updated about 2 hours ago