Access reviews on a schedule
Recertification campaigns run themselves. Reviewers get the justification and the account's admin activity since the grant, and can renew or revoke in one action.
Read moreAnswers to the questions the access team gets asked most, plus a way to reach a person when the answer is not here.
Shipped in the last two releases
Adding people, resending invites, and fixing sign-in problems.
12 articles
How access resolves, and how to grant the least of it.
9 articles
Enrolment, recovery, SSO, and what triggers a risk flag.
8 articles
Plans, seat counting, invoices, and reclaiming licences.
6 articles
The ten questions that account for most of our inbox
Check the Invitations page first — if the status is still Pending, the message was accepted by the recipient's mail server. It is almost always sitting in a spam folder or blocked by a corporate filter. Resending from the same page generates a fresh link and a new 7-day window. If two resends fail, ask their IT team to allowlist the sending domain.
Deletion is destructive and irreversible after the retention window, so it sits with Admin and Owner only. Managers can suspend an account instead, which revokes access immediately while keeping the record and its audit history intact. In practice suspension covers almost every case deletion is reached for.
Three things can override a role. Check them in order: the module may be disabled workspace-wide (Modules), an explicit deny may be set at group level, or their admin grant may have expired. The Access tab on their user record shows the effective result and names whatever granted or blocked each permission.
Their elevated grant is revoked automatically when the review closes — the base role is untouched, so they keep normal access and lose only the admin scope. Re-granting is a fresh request through the usual form. Reminders go out 14 and 3 days before the deadline.
A seat is consumed when an invitation is accepted, not when it is sent — pending invites are free. Suspended accounts keep their seat so it is there when they return; deprovisioning is what releases it. Service accounts count as seats on Business and below, and are free on Enterprise.
Yes, within the deleted-account retention window set in Settings (30 days by default). Restoring returns the account with its role, groups, and history intact, and consumes a seat again. After the window the data is erased and cannot be recovered from backups.
Risk scoring looks at device fingerprint, network reputation, geographic plausibility against the previous session, and how far the attempt deviates from that account's usual pattern. Two active sessions in places too far apart to travel between is the strongest single signal, and always scores critical.
No. Pages and permissions disappear for everyone immediately, but the underlying records stay exactly as they were. Re-enabling restores access with nothing lost. Data retention follows your workspace policy regardless of whether a module is on.
They should use a recovery code first — that is what they are for. If those are gone too, an Admin can trigger an MFA reset from the user record. The reset requires the account holder to re-enrol at next sign-in and is written to the audit log with the approving admin named.
400 days by default on Business, configurable in Settings. Beyond that, events move to cold storage and are retrievable on request rather than searchable in the dashboard. Enterprise plans can stream events to your own S3, Splunk, or Datadog for indefinite retention.
access@northwind.co
Replies within 4 hours, 24/5
#help-access on Slack
Fastest for quick questions
security@northwind.co
Suspected incidents · paged 24/7
Setup, theming, and the API