icon-zia.svg
Secure Internet and SaaS Access (ZIA)

Configuring End User Review

The End User Review is a type of Automated Workflow in 3rd-Party App Governance that allows you to maintain a leaner and more secure App Inventory, while engaging users in application governance.

In the review process, users confirm via Slack or email if they are using the apps currently enabled for them. Based on their response, their access to the app is either automatically revoked or maintained, and their response is recorded as a User Activity in 3rd-Party App Governance.

Initiating End User Reviews

You can initiate an end user review for all users or individual users of a connected app.

  • You can initiate an end user review for all users in the App Inventory or the App Panel header.

    • To initiate an end user review:

      1. In the left-side navigation, go to Inventory.
      2. In the App Inventory, go to the Automated Workflow column for the app.

      You can update the Automated Workflow of multiple apps at the same time. To learn more, see Taking Bulk Actions on Apps.

      1. In the drop-down menu, select End User Review.

      A review window appears.

      1. In the review window:
        1. (Optional) Add a note to share with users in the request for review.
        2. Choose whether to send the request for review to users via Slack or email.
        3. Click Review.

      Close
    • To initiate an end user review:

      1. Select the app.

      The App Panel opens.

      1. In the Automated Workflow drop-down menu, located in the App Panel header, click End User Review.

      A review window appears.

      1. In the review window:
        1. (Optional) Add a note to share with users in the request for review.
        2. Choose whether to send the request for review to users via Slack or email.
        3. Click Review.

      Close
    Close
  • You can initiate an end user review for individual users on the Access tab in the App Panel or User Panel.

    • From the Access tab in the App Panel:

      1. Select the app.

      The App Panel opens.

      1. Click the Access tab.

      1. Under Authorized User Accounts, click the ellipsis menu next to the user, then click Ask User to Review.

      A review window appears.

      1. In the review window:
        1. (Optional) Add a note to share with users in the request for review.
        2. Choose whether to send the request for review to users via Slack or email.
        3. Click Start Review.

      Close
    • From the Access Tab in the User Panel:

      1. Select the user.

      The User Panel opens.

      1. In Access > Top Apps and User's Permissions, click the ellipsis menu next to the app, then click Ask User to Review.

      A review window appears.

      1. In the review window:
        1. (Optional) Add a note to share with users in the request for review.
        2. Choose whether to send the request for review to users via Slack or email.
        3. Click Start Review.

      Close
    Close

Responding to End User Review Requests

Depending on your configuration, users receive requests to review their app usage either via Slack message or email.

  • If you configure the request for review to be sent via Slack, the user receives the following message:

    The user can submit one of the following responses:

    • I'm using this app: Access to the app is maintained.
    • I'm not using this app: Access to the app is revoked.
    • I don't remember installing it: Access to the app is revoked.
    Close
  • If you configure the request for review to be sent via email, the user receives the following email:

    Clicking the Review button redirects the user to the form:

    The user can submit one of the following responses:

    • I'm not using this app: Access to the app is revoked.
    • I'm using this app: Access to the app is maintained.
    • I don't remember installing it: Access to the app is revoked.
    Close

Depending on the platform (e.g., Google), access to the app can be automatically revoked. For example, if an individual user confirms the app is not in use and the platform supports the Revoke action, individual user access is automatically revoked. If all users of an app each confirm that the app is not in use and the platform supports the Revoke action, then access is automatically revoked and the App Status changes to Deleted in the App Inventory. To learn more, see Revoking and Banning Apps.

Reviewing End User Review Responses

After users submit their responses, the responses are recorded in the Activities tab of the App Panel and User Panel, as well as the Audit Log. To see user responses as they are received, enable the User Responded to App Review policy and configure notifications. To learn more, see 3rd-Party App Governance Policies.

Related Articles
About the 3rd-Party App Governance DashboardAbout the App InventoryApp Inventory FiltersSearching for AppsCustom ViewsPre-Vetting AppsUploading Apps in BulkTaking Bulk Actions on AppsClassifying AppsRevoking and Banning AppsConfiguring End User ReviewAbout the App PanelUpdating the App Risk ScoreUpdating the App Finding StatusAbout User InventoryAbout the User Panel3rd-Party App Governance Policies