Access certification (quarterly access reviews)

Review who can reach every restricted category, attest it quarterly, and export the evidence — the SOC 2 access-review ritual in one screen.

Every security framework asks the same question on a schedule: who can see the restricted material, and when did a human last confirm that list is right? SOC 2 calls it an access review; ISO 27001 calls it a rights review. Documents → Certification answers it for your document library in one screen.

FileDeck AI tierDocuments → Certification.

The review

The screen lists every restricted category with exactly who can reach it — allowed roles, client-area user assignments, and whether a shared password is set (with the honest note that password access is anonymous). Documents counts come straight from the live taxonomy; nothing is cached or approximated.

Review a row, fix anything wrong on the category itself (the certification screen deliberately never edits access — an attestation must describe the state that was actually reviewed), then click Attest reviewed. The attestation records who and when, in term meta for the current state and in the activity log as a certification event for history.

Quarterly by design

An attestation older than 90 days shows as due again, and the screen counts how many categories are due — glance at it once a quarter and clear the list. Attest all as reviewed exists for the disciplined case where you have genuinely walked every row.

The evidence

Export evidence CSV produces the auditor artifact: category, allowed roles, assigned users, password state, document count, last certification date, and who attested — one row per restricted category, dated in the filename.

Still stuck? Email support@getfiledeck.com.