User access reviews in ServiceNow, with evidence an auditor can test.
Warde runs user access review campaigns inside your ServiceNow instance. Reviewers decide in Employee Center, every revocation goes back to the system that granted the access and is confirmed, and the evidence pack shows exactly what was in front of each reviewer.
A review a line manager can finish without training.
Reviewers keep or remove access one row at a time or several at once, and can hand the review to somebody better placed to judge it. Each row shows how the access was granted, such as a request or an access bundle. Nothing is saved until they choose, and the screen confirms every decision.
Names are plain. A reviewer sees the application and what the access lets somebody do, not a raw entitlement string, because each entitlement is given a plain name, an owner and a risk rating when its application is onboarded.
The access stays
The decision is recorded with the person, the account, the entitlement, the reviewer, the reason and the time.
Removed down the request path
The revocation is carried out by your identity engine or a ServiceNow task, and confirmed back before the item reads as done.
Sent to the right reviewer
A review that belongs with somebody else goes to them, and the hand-over is part of the record. Platform delegates are honoured.
Defined, scheduled and run in ServiceNow.
Campaigns are defined and scheduled on the instance, so a recurring review of finance applications or of privileged access runs without anybody exporting a spreadsheet. A campaign runs once, daily, weekly, monthly, annually or on demand. Each one picks its reviewer: the holder’s manager, the entitlement’s owner, the application’s owner or the bundle’s owner, with a mandatory fallback reviewer so no line is dropped.
A campaign snapshots its scope, its reviewers and its rules the moment it launches, so an edit made afterwards cannot change the record of what was reviewed. A campaign cannot close until its revocations are confirmed.
The evidence pack answers the auditor’s first question.
An auditor asks whether the list under review was complete. A spreadsheet cannot answer that: months later, nobody can show which query produced the export, on what date, or that nothing was dropped between the export and the sign-off. The evidence pack can.
The pack reports the campaign as it was launched
Scope, reviewer strategy, every decision with its reason, who decided and when, read from the snapshot taken at launch.
A rename does not rewrite the evidence
Every line keeps its own copy of the person, the account, the entitlement, how the access was granted and when.
Taken away, and confirmed back
A revoke records the engine that ran it, the engine’s own reference and the stamp confirming it was carried out. Items the source system stopped including partway through stay in the pack, marked as withdrawn.
| Framework | What it asks for | What Warde produces |
|---|---|---|
| SOX 404 | Authorised provisioning, timely removal, periodic review, separation of duties | Approval records, confirmed removals, campaign evidence, SoD verdicts |
| PCI DSS 4.0 | Requirement 7.2.4: review accounts and access at least once every six months | Scheduled campaigns with a frozen scope |
| ISO 27001 | Annex A 5.18: access rights reviewed at planned intervals by the owner, and documented | Owner-led campaigns and the evidence pack |
| APRA CPS 234 | Access control sized to the threat | Campaigns for each application owner, with high-risk access on its own schedule |
| DORA and NIS2 | ICT risk management, including the review of access rights | Campaign evidence and history |
Warde is not a GRC platform. It keeps no control library and maps nothing to frameworks. It produces the evidence for one family of controls, in a shape an auditor can test. Every request, approval, removal and review decision is kept as insert-only history, for seven years by default.
With SailPoint, Microsoft Entra, or no identity engine.
With an identity engine, Warde reads what people hold from it and sends each revocation back to it. With SailPoint Identity Security Cloud or IdentityIQ or Microsoft Entra ID Governance, the engine stays the system of record. With no engine, access is imported and removals go to the team that owns the application as ServiceNow tasks. The reviewer screen and the evidence pack are the same either way.
What each vendor’s ServiceNow application does on your instance.
A tick means the work happens in ServiceNow. A dash usually means the vendor does it well in its own console.
| Warde | SailPoint | Saviynt | Entra | Okta | Omada | |
|---|---|---|---|---|---|---|
| Ask for access in the ServiceNow catalog | yes | yes | yes | yes | partly: the documented integration runs the other way, from Okta into ServiceNow | yes |
| Approve it in ServiceNow | yes | yes | yes | yes | partly: the documented integration runs the other way, from Okta into ServiceNow | yes |
| Your identity engine does the provisioning | yes | yes | yes | yes | yes | yes |
| User access reviews decided in ServiceNow | yes | yes, for Identity Security Cloud: SailPoint documents a certification portal in ServiceNow where certifiers approve, revoke and sign off | no | no | no | no |
| Campaigns defined and scheduled in ServiceNow | yes | their console | their console | their console | their console | their console |
| Approval policies built in ServiceNow | yes | no | no | no | no | no |
| Access bundles curated in ServiceNow | yes | no | no | no | no | no |
| My Access: one page for what you and your team hold, and the reviews waiting on you | yes | partly: the app shows the roles and access profiles a person holds, without a team view or reviews on the same page | not stated | their console | their console | not stated |
| An admin workspace on the instance: what is stuck, what is stale, connector health | yes | not stated | not stated | no | no | no |
| The auditor’s evidence pack, in ServiceNow | yes | no | no | no | no | no |
| Runs with no identity engine at all | yes | no | no | no | no | no |
| Spots the joiner and the leaver for you | not on its own: your own joiner and leaver trigger calls Warde’s lifecycle endpoint, and Warde provisions from there | yes | yes | yes | yes | yes |
Read from each vendor's published documentation in September 2026. For Okta, "partly" means the documented integration runs the other way: a request raised in Okta creates a record in ServiceNow. For SailPoint on the My Access row, it means the app shows what a person holds, without the team view or the reviews waiting. SailPoint's tick on user access reviews is for Identity Security Cloud's Store app, which SailPoint documents as a certification portal where certifiers approve, revoke and sign off. The IdentityIQ integration does not include it. On the last row, Warde does not watch your HR feed. Whichever system already knows somebody has joined or left calls Warde's lifecycle endpoint, and Warde grants or removes the access from there. The full sixty-three-row version, sources attached, is yours if you ask for it.
User access reviews in ServiceNow, answered.
What does Warde add to ServiceNow for access reviews?
A scoped application that runs the whole review on your instance: campaigns defined and scheduled in ServiceNow, reviewer screens in Employee Center, revocation through the same path as a request, and an evidence pack.
Which systems can a campaign review?
Anything Warde knows people hold: access read from SailPoint or Microsoft Entra ID Governance, and access imported for applications with no identity engine behind them.
Is a revocation actually carried out?
Yes. A take-away decision becomes a removal that runs the same fulfilment path as a grant. The item is marked done only when the engine confirms the change, or when the ServiceNow task for the owning team is closed complete.
How often should we review access?
Quarterly satisfies SOX, PCI DSS 4.0 requirement 7.2.4, ISO 27001 Annex A 5.18, APRA CPS 234 and DORA and NIS2. Privileged and high-risk access can run as its own campaign on a tighter schedule.
Do reviewers need a new tool?
No. Reviewers work in Employee Center, which staff already use. Warde is installed from the ServiceNow Store as one scoped application, and is waiting on Store certification.
Related pages
Bring last quarter’s review spreadsheet.
Forty-five minutes on a live instance, with no slides. We will show you what replaces it, what it costs, and what the product still cannot do.