Exemptions

An exemption lets you temporarily suppress a violation when a legitimate business need justifies the conflicting access. Exemptions are time-bound and Zluri automatically re-opens the violation when the duration expires.

Exemptions must be enabled per policy. Turn on Allow Exemptions in the Remediation step when creating or editing a policy. Only Owner, Admin, and IT Admin roles can grant exemptions.

Exemption statuses

The following statuses appear in the Status column of the exemptions table.

StatusMeaning
ActiveThe exemption is current and suppresses the linked violation.
ExpiredThe exemption duration elapsed. Zluri re-opened the linked violation automatically.
RevokedThe exemption was manually revoked before it expired. The linked violation returned to Open status immediately.

Grant an exemption

Steps

  1. Open the violation by selecting its row or choosing View from the row actions menu.
  2. Select Exempt in the drawer header.
  3. Enter the exemption duration in days. The Create Exemption panel shows the max duration allowed by this policy inline (for example, "Max allowed in this policy: 30 days").
  4. Enter a Reason. This field is required.
  5. Select Create Exemption. Zluri moves the violation to Exempted status.
Create Exemption panel with Duration field, max-duration note, required Reason field, and Create Exemption button

Zluri automatically re-opens the violation and returns it to Open status when the exemption duration expires.

View and manage exemptions

View exemptions from two places:

  • Global exemptions page: Navigate to IGA > SoD > Exemptions in the left navigation to see all exemptions across every policy in your organization.
  • Per-policy Exemptions tab: Open a policy from Policy Library and select the Exemptions tab to see exemptions for that policy only.
Global SoD Exemptions page showing two exemptions with Exemption ID, Status (Expired and Active badges), Policy Name, Identity Name, Reason, Created By, and Expires At columns

The exemptions table shows the following columns.

ColumnDescription
Exemption IDThe unique identifier for this exemption. Select it to open the exemption detail drawer.
StatusThe current status: Active, Expired, or Revoked.
Policy NameThe policy the exemption applies to.
Identity NameThe identity covered by this exemption.
ReasonThe reason entered when the exemption was created.
Created ByThe user who granted the exemption.
Expires AtThe date and time the exemption expires.
ActionsThree-dot menu with Copy Link and View options.

Use Active Exemptions to show only unexpired exemptions. Select the filter icon to refine the list by additional criteria. Use the column picker to show or hide columns.

Select the three-dot menu at the top right of the table to Refresh the list or change the View Density between Compact and Comfortable.

Revoke an exemption

Steps

  1. Select the exemption row or choose View from the row actions menu to open the exemption detail drawer.
  2. Review the three sections in the drawer to confirm the scope before revoking.
Exemption detail drawer showing Active status, days remaining, Revoke Exemption button, and Violation/Policy/Exemption Details sections

The drawer shows the following sections and fields.

Violation Details

FieldDescription
Violation IDThe unique identifier of the linked violation.
Detected atThe date and time Zluri first detected the violation.
Entity TypeThe type of identity (for example, User).
UserThe identity name.

Policy Details

FieldDescription
Policy NameThe policy that raised the violation.
Run atThe date and time of the detection run that created this violation.
Execution IDThe identifier of the detection run.

Exemption Details

FieldDescription
Created byThe user who granted the exemption.
Created atThe date and time the exemption was created.
DurationThe total duration of the exemption in days.
Expires atThe date and time the exemption expires.
ReasonThe reason entered when the exemption was granted.
  1. Select Revoke Exemption. Zluri sets the exemption status to Revoked and returns the linked violation to Open status immediately.


Did this page help you?