Exemptions
An exemption lets you temporarily suppress a violation when a legitimate business need justifies the conflicting access. Exemptions are time-bound and Zluri automatically re-opens the violation when the duration expires.
Exemptions must be enabled per policy. Turn on Allow Exemptions in the Remediation step when creating or editing a policy. Only Owner, Admin, and IT Admin roles can grant exemptions.
Exemption statuses
The following statuses appear in the Status column of the exemptions table.
| Status | Meaning |
|---|---|
| Active | The exemption is current and suppresses the linked violation. |
| Expired | The exemption duration elapsed. Zluri re-opened the linked violation automatically. |
| Revoked | The exemption was manually revoked before it expired. The linked violation returned to Open status immediately. |
Grant an exemption
Steps
- Open the violation by selecting its row or choosing View from the row actions menu.
- Select Exempt in the drawer header.
- Enter the exemption duration in days. The Create Exemption panel shows the max duration allowed by this policy inline (for example, "Max allowed in this policy: 30 days").
- Enter a Reason. This field is required.
- Select Create Exemption. Zluri moves the violation to Exempted status.
Zluri automatically re-opens the violation and returns it to Open status when the exemption duration expires.
View and manage exemptions
View exemptions from two places:
- Global exemptions page: Navigate to IGA > SoD > Exemptions in the left navigation to see all exemptions across every policy in your organization.
- Per-policy Exemptions tab: Open a policy from Policy Library and select the Exemptions tab to see exemptions for that policy only.
The exemptions table shows the following columns.
| Column | Description |
|---|---|
| Exemption ID | The unique identifier for this exemption. Select it to open the exemption detail drawer. |
| Status | The current status: Active, Expired, or Revoked. |
| Policy Name | The policy the exemption applies to. |
| Identity Name | The identity covered by this exemption. |
| Reason | The reason entered when the exemption was created. |
| Created By | The user who granted the exemption. |
| Expires At | The date and time the exemption expires. |
| Actions | Three-dot menu with Copy Link and View options. |
Use Active Exemptions to show only unexpired exemptions. Select the filter icon to refine the list by additional criteria. Use the column picker to show or hide columns.
Select the three-dot menu at the top right of the table to Refresh the list or change the View Density between Compact and Comfortable.
Revoke an exemption
Steps
- Select the exemption row or choose View from the row actions menu to open the exemption detail drawer.
- Review the three sections in the drawer to confirm the scope before revoking.
The drawer shows the following sections and fields.
Violation Details
| Field | Description |
|---|---|
| Violation ID | The unique identifier of the linked violation. |
| Detected at | The date and time Zluri first detected the violation. |
| Entity Type | The type of identity (for example, User). |
| User | The identity name. |
Policy Details
| Field | Description |
|---|---|
| Policy Name | The policy that raised the violation. |
| Run at | The date and time of the detection run that created this violation. |
| Execution ID | The identifier of the detection run. |
Exemption Details
| Field | Description |
|---|---|
| Created by | The user who granted the exemption. |
| Created at | The date and time the exemption was created. |
| Duration | The total duration of the exemption in days. |
| Expires at | The date and time the exemption expires. |
| Reason | The reason entered when the exemption was granted. |
- Select Revoke Exemption. Zluri sets the exemption status to Revoked and returns the linked violation to Open status immediately.
Updated 13 days ago