Video: Personnel Security & Access Reviews Workshop | Duration: 3640s | Summary: Personnel Security & Access Reviews Workshop | Chapters: Welcome and Introduction (13.055s), Session Overview (97.325s), Access Reviews Overview (258.315s), Integration Setup (354.68s), People and Groups (885.09s), API Workarounds (2259.63s), API and IDP Integration (2374.76s), Technical Support (2451.98s), Future Development (2586.37s), People Profile Management (2629.595s), Wrap-Up and Feedback (2859.925s), Closing Remarks (3617.555s)
Transcript for "Personnel Security & Access Reviews Workshop":
Hello, everyone, and welcome to Venta's personnel security reviews I mean, personnel management and security review session. I'm Jaquez, and I'll be your facilitator today. We're gonna get things started shortly here. We're just gonna give, one more minute for those who signed up to enter into the room. In the meantime, I'm gonna put a prompt in the chat here. If you could introduce yourself, let us know where you're joining us from. What's going on, Brian? It's good to see you again from ATL. Welcome. Welcome. Feel free to start some conversation in the chat. We're gonna begin momentarily. Alright. Let's go ahead and get this in motion. For those who've just entered into the room, I'm Jaquuez. I'm the program manager for down market education here at Vanta, and I'm excited to take you through how to manage your team inside of Vanta, setting up those automations, etcetera, and, also, what access reviews are and how you can implement those into your, quarterly, monthly, weekly, whatever requirements you have in place when it comes to managing those permissions. One way that I love to host my sessions is that if you have any questions, feel free to ask as we go. What I'll do is after I speak on a specific, topic, I will toggle my screen back to see if you have any questions about that specific area before I move forward. If you wanna wait towards the end, feel free to do that as well. I'll definitely stick around, the end of this training to answer any open questions. Now before we begin, let me take a look again in the chat and see who we have joining us today. We have Brian coming in from ATL. Now yeah. Good to see you again, Brian. Welcome back. Donna from Saint Petersburg. Welcome, Donna. And we have Adham from Israel. Welcome, Adham. Alright, team. Let's go ahead and get this in motion here. Let me move this out the way. One moment. Alright. Perfect. Let's just go through the expectations for today. I kinda spoke about it briefly, but let me kinda go through specifically what we're going to cover. We're gonna first go through, why we perform access reviews and kinda give some background before we get started. And then we're going to hop inside of the product, and we're gonna start with our integrations. And we're gonna discuss the key ones that you need in order to power up your team. From that point, we're gonna talk about those groups and checklists. So we're gonna, go through the process of setting up a team, how it runs inside of Vanta, how you assign those task and policies, and more importantly, ensuring that everyone is on the same page. And then we're gonna go through the process of performing and managing an access review, and there's two different methods to make that possible. We're going to discuss one and do the other because it's more extensive, the actual one that we're gonna do live. But it's going to help you to really understand that process so that way you're able to move forward effectively. And then, of course, towards the end, if you have any questions, I'm gonna stick around to answers though answer those. So feel free to, you know, definitely either ask as we go, or you can wait towards the end if you would like. Now I have a couple of slides before we actually dive into the product, but let's go ahead and start here. Let's discuss why we perform access reviews. Now for many of you, you're probably aware of this, but it's necessary, and auditors look for some type of process in place, that shows that you're pruning privileges. Right? Let's just discuss the three main components. The first is security. So we want to ensure that only authorized users can access any sensitive data, and this is going to reduce the risk of breaches or any unauthorized activity. Second is compliance. So many of your frameworks, they require proof that you're actively controlling and reviewing who has access to your critical resources. And then finally, the third one, efficiency. Rightsizing permissions prevent excessive privileges, making everyone workflow smoother while minimizing potential risk. Now what is an actual access review? I'm gonna discuss it, and then I'm gonna show you, later on in the demo. But these access reviews are regular check ins to evaluate and manage user permissions across various systems, across your applications, and any data. So by periodically confirming that each team member's assets matches their role, you can prevent any accidental overexposure of data. You can keep your environment organized, and more importantly, you can meet the principle of least privilege. Now we're gonna see exactly how Vanta streamlined these reviews later in the session. Now let's go ahead and hop inside the product. That's my last slide there. And let me show you exactly how we manage your team inside of Vanta. One moment here as I pull up that demo environment. Perfect. Perfect. Let me check to confirm you can see what I see. Alright. Now the first place we wanna start is our integrations. And if you've taken our Vanta sensuous training, a few of these will sound familiar, but they're very important when it comes to powering up your team inside of Vanta. So there there gonna be four that may sound familiar, but I'm gonna give you a fifth one, that is very important when it comes to personnel. Now the first integration that we suggest is your identity provider. So we're gonna select add integration here. We're gonna search by keyword, and this is gonna provide you with a list of every single IDP that Vanta connects with. Now this integration brings all your personnel into Vanta, and this specific one is crucial for that onboarding and onboarding process. Now integrate with a lot of your big name IDPs, but let me just point out some of the benefits here because though we are giving you the core ones that you need for your personnel, we do suggest that you connect every single one of your integrations that we support inside of Vanta. And one of those reasons leads to your overall compliance, journey here. Because, of course, that framework that you're going after, many of your controls, they are satisfied by some of your integrations. So let me just open up this, Vanta oh, not Vanta. Onto our Office three sixty five one real quick here. First and foremost, if we have a guide in our help center, you're gonna see a link to access that. The overview gives you just an overview of what this integration is. And the automation section is what I wanna focus on here. Because, specifically, this integration is gonna help you automate four tests and help you pass 55 controls. And you can select this to see specifically which test will be automated and which of those 55 controls is going to help you pass. Okay? Now this is gonna be extremely helpful because if you're, you know, trying to get things started and you're the type that need to see some type of progress in order for you to get excited about it, connecting your integrations will definitely get you to that point. Okay? So ultimate suggestion, connect every single one of your integrations that we currently support inside of Anthem. Or if we're just getting started here and you're focusing on personnel and you just wanna see how things flow, connecting your IDP is definitely one of those good options. Now the second integration that we suggest is your task tracker. Now this integration is very important because it allows you to assign remediation tasks directly within your tools. Now the reason why this will be a key factor is that when you are performing those assets reviews, most organizations have a different department that handles, any additions or removals from any tools. So having your third party, task tracking app connected or task management app connected allows you to connect with your IT team, security team, or whoever, in their common environment, to assign that specific task for them to update permissions for a specific user. Now I'm gonna show you what that looks like once we go to our access review section within the demo, but this is gonna be extremely helpful when it comes to that, not text. I almost said text. I don't know why I said text. But in your personnel settings, when we go to the access reviews, it's gonna be very pivotal. This will also be used in other features, so definitely connect that. It'll be extremely helpful. So we have identity provider. We have your task tracker. The third is your HR information system, aka your HRIS, and I should have known it well. Thanks for that. There we go. Now this integration is important because it helps you track your employee start and end dates. Now we integrate a lot of your big name HRIS systems, so definitely feel free to connect the one that your organization use. If you don't see, the tool listed that your team use, by all means, select this request integration link here, complete the form in its entirety, and our team will, try to see what they can do to make that possible. If you don't have a, HRIS system, I will show you the manual route on how you can add that information in. And then the fourth integration that we suggest is your mobile device manager, aka your MDM. Now this integration is key is it just MDM? Okay. There we go. Now this integration is key because it allows us to ensure that your devices meet security standards like encryption or antivirus requirements. Now we integrate with a lot of your big name MDMs, so definitely keep that in mind. But for those of you who do not have an MBM, Advanta, we have something called the Advanta device monitor. I'm gonna share that link in the chat. And this specific integration here can be used as a lightweight alternative because what it does is it checks, if your employees' devices meet security basics. Now remember, it's a lightweight alternative, and our rule of thumb is that if you have over 50 people, definitely invest in the MDM. It's gonna be 10 times easier and helpful, and it comes with better security features for you and your team. But if you have under that amount, the Vanta device monitor will be a great option to assist you along the way. Now here's a strategy that I share my Vanta essentials training for those of you who are brand new, to, Vanta in our live training suite here. Here's one strategy that you can use as well. First and foremost, the MDM connection, we allow you to connect as many MDMs as you need to. So if your organization uses multiple MDMs, you can connect each of those accounts inside of Vanta. And for those of you who, you know, you want to be strategic about your licensing and etcetera, one strategy that I suggest is that if you hire contractors, instead of adding them to your MDM, have them, use the Vanta device monitor. It's a free option. No cost to you. No cost to them. And it frees up your licenses for your MDM for full time, part time employees. So, definitely, you can use that option. It it's definitely accessible to you at any time. And then the final integration that we suggest is security trainings. Now this integration is key, if you have any of these, approved integrations here for security training software. Okay? So if you're using Curricula, Docebo, EasyLama, which is a very popular one, KnowBefore, etcetera, you're able to connect your security training software with Vanta and then assign, trainings to your team. Now if you do not have or if you're using some custom made security training that your organization created, I'm gonna show you how to manually do that inside of your groups. But if you do have any of these, feel free to connect these now because it will allow you to assign those security trainings easily for each employee without you having to manually do anything, on your end. Alright. Now these are the core integrations that we suggest to power up your personnel section. But definitely, rule of thumb, connect as many of your tools that we support. Because when it comes to your asset section, it's going to help you to know who has access to what. Up next, we're gonna go inside the personnel or the people tab. But before we do that, let me check the chat, see if we have any questions about this section. Alright. Looks like we're good to go. Perfect. Perfect. Alright. We're gonna go ahead and go to the people section. Now this is gonna be located in personnel, then people. And on this page here, you're able to see every single individual that has been brought in, AKA your identity provider here. Okay? So your IDP plays a huge role in this section here. Now what's great about this is that, this, specific feature, allows you to ensure that your team is fully compliant. Now the reason why I shared that is I want you to look at the people section not as a day to day to do list. Okay? Look at it as a part of your compliance program. What do you need in order for your team to be compliant? Okay? Now let me start with groups so we can kinda tie this story in together, and then we're gonna come back to this people page. Remember, the people tab is to confirm that your group I mean, that your team is compliant. And in this group section is how you ensure that compliancy is met. Each and every one of you have what we call the default group. Let me open this up here. Now this default group is your catch all group. So anyone that is brought in AKA your IDP, they're gonna be brought into this specific group. Now the benefit of this is that since this is a catch all group, you can treat it as company wide requirements. So whatever anyone in your organization needs to be fully compliant company wide, you wanna add those items here. So any company wide policies, you wanna make sure those are here. Company wide trainings, those are added here. Device monitoring, background checks if you're gonna use that. And then any onboarding and offboarding tasks, you wanna make sure those items are added here. Now we're gonna break this down even further once we create a specialized group, but I wanna kinda break down or kinda showcase to you how this works because, usually, when we're seeing anything that's team related, we treat it as, okay. If I have any random task, I can just assign it to any team member here, and we're good to go. But I wanna enforce the idea that anything inside of your Vanta account that you see, it is for your compliance and security program. Okay? So anything that needs to be compliant, that your team needs, you wanna make sure you have that here. If we were looking at vendors, it'll be the same way. How do I ensure that vendors are compliant that we're working with? I wanna make sure I have that information listed here. You wanna thank big picture, which is your audit. Right? Your auditor is going to come into your Vanta instance, Well, the audit of you of your Vanta instance, and they wanna confirm that everyone and everything in your organization is compliant. So the goal is to ensure that in the people section, your team is compliant. So specific frameworks, they have different policies that all teams must read and acknowledge. They have specific training, so they wanna know that you have some type of ongoing training that keeps them in the, you know, loop of different, protocols for different levels or measures that could happen. And then, of course, you wanna make sure that you're, documenting specific action items that each employee must complete. Okay? Now I'm gonna go back because I want to show you how to create a specialized group. And then from that point, we're gonna go in-depth into each of those features here. Now remember, in your instance, you're going to see this default group. You'll probably not see any of these specific groups listed here, but seeing that default group would be the first of you that you have in your group section. Now there's multiple ways that you can create a group. If you have specific groups in your IDP already created, if you select add group and then add from identity providers, whatever group segments you have in place, you can easily create your specialized or custom groups from those, IDP layouts. Okay? So keep that in mind. So if you already have something already categorized already, ready to go, and maybe you have a segmented based on sales, customer service, or tech support, and then product team, you can just automatically bring those over. And then from that point, you can build the context of your group on the inside. Let me go back here. We're gonna select add group and then create a group. You wanna give it a name. I'm gonna put, j engineers here. We're gonna create a engineer department group. Description, now this is helpful, especially because at Vanta, we highly suggest you have more than one admin. So if you ever have to go out of town, etcetera, or you're out sick, they will know exactly what to do or what each section means that you created. So we do suggest you put a description. I'm gonna put testing for the sake of this demo. And then the point of contact, we highly suggest that if you do use this feature, that the point of contact is someone who has knowledge of that department, of that team, who can do admin tasks, complete certain items that are required. So you wanna make sure you're choosing someone here that best fits that protocol. I'm gonna make it myself for the sake of this demo, and then we're gonna select create. You're gonna see at the bottom that the group has been created, and we're gonna search for it, and we're gonna open it up. Now this group is completely bare. So it has nothing inside of it, and not even people connected to it in order for it to be active. Okay? Now here's a strategy that I highly suggest you use when you create your specialized group. Remember, your default group is your catch all group, and I want you to treat it as company wide initiatives, which means anything that everyone in your entire organization needs to do, you wanna make sure it's captured in that group. Now department specific items, you wanna create that or put that in your specialized groups. So for example, engineers usually have additional requirements that are not company wide. So they have additional policies, trainings, onboarding tasks they need to complete that goes beyond the scope of the general onboarding experience. Right? So we wanna make sure we're capturing that inside of this group. Now before we even add members to it, we wanna add the context inside of the group. And the first thing we want to explore is the policies. So we're gonna select add here. Now this list is every single policy that has been approved. Okay? The reason why I make I wanna make sure that I say approve is that if you happen to go here and not see a policy that you want to assign to a team and you know you uploaded it inside of Vanta, it's going to be because of this reason. I'm gonna show you this very quickly here. We're gonna go to policies, compliance policies, and let me move that here. We're gonna just we're gonna say it's the third party management policy. Right? Let's say that's the policy you're trying to assign to your engineer group. The reason why you don't see it is that the status of it is needs remediation, and the version is still in draft mode. It needs to be completely approved and okayed in order for it to be accessible when you're assigning it to a group. So to do that, you're gonna go inside the policy. You're going to follow whatever steps need to be put in place. Gonna make myself an approver very quickly here. Hit submit. You wanna go through any next steps. If there is any next steps that will come up. In this case, by making myself the approver, we're good to go. Now if I go back to my group here, we're gonna scroll down, go to personnel, people, groups, j engineers. And if I want to add the third party management policy, it should appear here. Hold up here. Let me go back. Personnel. People, groups. I need to reset here. Enter. Add. It's not supposed to do that here. It's like I'm restricted on certain items. Let me check something very quick here. I think someone has changed the requirements here for my account. Compliance. And if it doesn't adjust the way I need to, we're just gonna keep it moving, but let me make sure we're good here. Fully approved. Good to go. Groups to engineers. If it doesn't work, I'll just speak through it because I think someone changed my permissions. Yeah. I don't have access to every framework here. Okay. In your case, if you were to go through that process, you should see whatever you approved to appear in your policy section for that specific group. Okay? My apologies. I hate that you couldn't see it on this side. I'm gonna have to look into that in the back end and figure out what toggle someone turned on, but you should be able to see it on your end. And then from that point, you'll just add it let me just try this one more time. So interesting. You'll just add it to that specific list. I'm just gonna choose some here. And then now that's gonna be a requirement for any engineers that we bring inside of this group. Okay? Now that's the simple, easy, smooth process when it comes to policies. One key fact is that, remember, if you don't see a specific policy and my not in my case, of course. Right? If you don't see a specific policy, it's only due to the fact that it hasn't been approved or cayed, or you don't have permission to a framework. I forgot we definitely have those granular permissions. I think most of the use cases on this call wouldn't fall as that second category, so definitely keep that in mind. Now if you do happen to go through that same scenario I went through, definitely select this question mark icon here, chat with us, and get connected to a support team member so they can look into it further. Okay? Now let's look at trainings. Remember, I shared that if you connect your security training integration, you'll have the ability to add them to a specific group. Now out of the box, you should have access to Vantaa's security trainings. And that's basically our general trainings that we've created that you can use for any occasion. So let me just show you what it looks like here. If you were to toggle on one of these specific trainings, you'll see the Vanta option appear. Okay? Now if you had your third party integration connected, you're gonna see Vanta plus whatever, specific software you're using. You'll be able to select from those options. Let me toggle these three on because I'm gonna show you something very quickly here. We're gonna go to new training because I wanna show you what it looks like if you have your own custom training. We're gonna choose a category. So let's just choose AI risk training here, and then we wanna select custom training. Now remember, this use case is for those specific individuals who, has a security training that was created in a tool that we don't currently support, Avanta, or maybe you're using Google, etcetera, to build out your training platform for your team. What you'll do is add the URL for that training. Okay? Let me do that was two of those. And then you can add in some additional instructions on what you want them to do, towards the end or during that specific training. K? Now we're gonna select add here so you can see what it looks like. And now you see a custom training in the AI risk section. Now I'm gonna leave that as is so that way we can I can actually show you the difference between the two? But this is how you would add in a custom training if you do have something that doesn't integrate directly with Vanta. We're gonna select save, and you're gonna see those two trainings listed. Now I'm gonna show you towards the end how you can take a look at specific things. But you know what? You know, let me go do it now. We're gonna select it now so you can see it. Preview task here. So as you're building things out, you're able to see specifically how things look. And the reason why I wanna show you this is because in that custom training, you now see that there's a link connected here. So that way, they just select it. It's gonna take them to that specific site, in this case, vanta.com. And then once they're done, they're gonna upload a screenshot of that final screen, and this is gonna serve as your evidence to confirm they've completed that specific item. Now if you want to, capitalize and document it, in a third party, you know, tool, maybe you have, like, a Google spreadsheet or something like that, you would have to go to their profile and confirm or whatever system you have in place if you're using Google Forms, etcetera. You'll just take those options to confirm they've completed that specific item. And then from that point, they're good to go. If you're using Vanta's training, this is how it will look. And what is great about the Vanta trainings, and I think even the third party integrations work this way as well, if they were to click off the screen, the video will stop. So they have to remain on the same page. They can't have multiple screens open. This is to confirm they're actually watching and reviewing the material. And then we have our policy that we've already put in place as well for them to read and to accept. Well, let's continue on because we have more information to explore here when it comes to this group setup. So let's take a look let's take a look here at the device monitoring. Now because you already have your third party integration connected for your MDM, nine times out of 10, you won't have to do anything with this option. But let's just say maybe you're gonna create a group for those contractors. You could, select this option to have them install the Vanta device monitor. Okay? So this will alert any member that is added to the specific group, especially if their profile does not have an MBM for them to download and install the Vanta device monitor. Okay? We're gonna uncheck this for the sake of this example. Now background checks, this is a feature that you can use if you have that connection. You're able to use our third party connection connector here in order for you to, you know, run background checks. This is for those specific use cases. Maybe you have a specific group of, you know, individuals that you want to use this for. You can definitely do that. But I just wanna point this out because it is an available feature for those who want to use it and have access to it. Okay? Now let's go to this custom onboarding task. We're gonna select add here. Now this is where you can get extremely powerful and tedious. So, for example, if we're thinking about onboarding, right, and we're thinking about items that we need in order to confirm that this person and this this team, this department is compliant, what items do we need to request from them? What items do we require for them to complete? So what you can do, if you select create a custom onboarding task, you can build out those items. You can start out by giving it a task name, and then we allow you to go even further to where you can add in-depth instructions here. Okay? Now here's where we can really get strategic with our task. You can create admin specific task, which means anyone that is an admin that is involved in this group or, let's just say, the point of contact in this group or who is a admin inside of Vant in general, they will see these tasks, and they will know that these are admin specific tasks they need to complete. Then you have personnel task, and this is the task that any member that is added to this group is going to complete. So once you create create this group, you make it live, you add the team members, they're gonna be alerted via email to complete any listed task for this specific group. Then from that point, you can make this task even more robust to where you can have it to where maybe this is a question where you want them to provide you with a, you know, screenshot of their ID. You can turn this toggle on and have them upload a file so that you can actually store whatever you need based off of the question inside of Anthem. Or if you want them to respond with a text response, you can have that as well. So maybe in this case here, right, add their YubiKey number. You can have them type up their response here. You can be as specific as possible or strategic as possible when it comes to creating an onboarding task inside the, group section. Now one thing I wanna point out is that once you create a task, this functions as a running list. So over time, you're gonna see this kinda grow out based on the amount of tasks that you create. So one strategy here would be to audit these occasionally to ensure that each of these tasks are still fundamental for your day to day, your quarter to quarter, your, you know, year to year. Okay? Now I'm gonna add some that I created just so you can see what it looks like, and we're gonna select add here. And now we have those tasks listed. So let's go to our preview section. I'm gonna scroll down here, and now you see these two tasks that were added. So if we want them to upload something, we have that option here. If we want them to where's that other one? Oh, let me go back here. I think I deselected one. Oh, no. It's for admin task. My apologies. Yeah. So the admin, you wouldn't be able to see on that end. It's admin view behind the scenes, but you're able to see specifically what items you want them to have, provided. So you can use this as strategically as possible. But, again, think of it this way. Remember, you wanna separate the ask for anything company wide. You want it to be in that default group, but anything department specific, you wanna add to the your specialized custom group here. And then we have our onboarding section. Now this specific section here is how you kinda handle what needs to be done when an employee is no longer with your organization. Now let's take a look at this assets removal tab. We're gonna select add here. Now tying back to what I shared earlier, it is very important that you connect as many of your tools with Vantage as possible. Because from that point, we can literally list out every single system that you have approved here, and we can make it to where depending on, you know, how you're using using it, etcetera. You're able to choose what specific tools that, based on this department, needs to be removed from their profile when they are no longer with your organization. So let's just say, you know, these are engineers. We're gonna say, let's do this AWS. We're gonna do Atlassian. We're gonna do anthropic. I'm gonna add one more Microsoft here. Gonna add those four systems. Now any employee that's added to this group, if they're ever terminated, they're gonna the admin is gonna be required to remove them or get the process in motion to remove them from those tools. Another thing, as an admin, you're able to create custom off boarding task that you need to complete to successfully off board this employee. So whether it be, you know, having that scheduling a meeting for that off boarding conversation or, you know, having removing them from, the Slack channel, etcetera. You can be as particular as possible when it comes to off boarding an employee here. I'm just gonna choose a couple of items here so that way they can you can actually see what's there. And then from that point, if we select save, save again, this is just confirming what we have. We now have our group created. The next step will be to go to the member's tab, and this is where you're at those people and to this specific group. Okay. And that is how you create a group inside of Vanta. Now up next, we're gonna take a look at, that profile tab or the people tab one more time and kinda see how all of this ties together before we take a look at those assets reviews. Well, let me check the chat here, see if we have any questions about any of this. Let's see. Brian, you said, can I automate moving users to groups based on another activity, e g move user into CUI dash access group once CUI training has been completed? That's a great question. I think for that in order for that to be done let me confirm here. That may require let me actually let me pull this up first before I actually share that. I wanna make sure I'm giving you the right context. See. Because I wanna make sure. I know we have a a lot of different rollout of behind the scenes features. I wanna confirm that there isn't something new that we've released that could make that possible in a easy way. One moment here. Still going through the process. Yep. And that's exactly what I thought. Okay. So to answer your question, not really or natively within Vanta, but there is some, you know, sort of workarounds. And the one that I think will work best would be the external automation with the API. Yeah. Because the Vanta's API would give you that ability to kinda control that specific, you know, result. But you have to, if I'm not mistaken, use it with an automation tool like, you know, Zapier or some type of custom script in order for it to be something that you can actually move around. Let me see here. Let me see if I can actually find a let me see if I can find an article on our API here that will be helpful. Yeah. Because that'd be a good one. You said do the groups created in Vanta replicate to my IDP? Great question. We don't it doesn't actually replicate to your IDP. If you're using if you're using an IDP group that, was created from, you know, the instance when you connected your IDP to Vanta, it was on your list of IDP connections, then they do kind of segment to each other. But if it is one that you created inside of Vanta, it doesn't speak to your IDP. Yeah. It doesn't speak to it. I'm gonna give you these two articles here. And I even have yeah. Let me share this as well. Specific endpoints for the groups that you can use, and this should be helpful as well. Oh, I hope this link goes through great. Let me see. Yeah. I wish I can edit that. Let me see here. Yeah. So the only thing about this, this, tool here that we're using for our live trainings is that when we copy and paste something, it shows totally different until we actually hit enter, and then it blends it together. Let me try to separate space a little bit more here. Let me see. And then I'm a have you use this one instead. Let's see if that looks better. Still blending certain ones in there. One moment here. Let me see if I can actually send it to you in a clearer format, and then we should be good. Okay. It's doing the same thing here. Alright. Let me go back to the chat area. Yeah. Allow me to I'm gonna what I'll do is I'll mass email this to the entire group after the call because the links aren't separated where I needed to so that way y'all have the full complete. It's blending in some of the keywords with the URL, and that shouldn't be the case. But, Brian, I'll definitely share that with you so that way you have it offline. Elizabeth, you say you have to drop off early, but you're most interested in understanding the assets review portion. Yes. It is recorded. Yeah. This entire session will be recorded, and you're going to receive a link in twenty four hours to review the entire session. Yeah. That's a great question. So you'll definitely get that. You're good to go. Perfect. Perfect. Alright, team. But, yeah, Brian, just speak on it, verbally again. It is a way. You just have to use the API component, which will then allow you to kinda automate it with that third party tool. But, yeah, it's a good question. That's a good question. Hopefully, our AI will get to that point because I know we're working on some things currently to where, we're we're really you've really got some good stuff in the works. I'll just leave it like that because I'm not I don't like to give it out there and then they change the dates and then you're waiting another six months because they had this hiccups in the process, but there's some great things coming that will also assist in that area as well. Yeah. No problem at all. No problem at all. Alright, team. Let's take a look at that people page very quickly because now that we have our groups created, everything you see in these profiles are gonna be based on the group they've been added into. So any tasks that are listed here is based on the groups that they've been assigned to. Okay? As you can see, they're in the default everyone group, and they've been added to two additional groups on top of that. So because of that, whatever task are inside of those groups are gonna be in their list here. Now you shouldn't see a lot of overdue. Again, I'm in a test environment the entire organization use. You're gonna see a lot of rare use cases here. But this is the, really, the sentiment of what you should see in your day to day. And what is great about this is that even once they completed their task over time, you're gonna be able to see a full list at the bottom of every single task they've completed. Now this is gonna be helpful for audit purposes, also, just for some documentation purposes where you wanna confirm that an employee did complete something at a certain time period. Okay? Then that access tab. Now as you connect all of your tools to Vanta, we're able to show you exactly which tools each member has access to. This is gonna be extremely helpful because you're able to see, you know, where your, you know, permissions are currently set up for specific users, who probably don't need these specific, permissions, especially when you're in the profile. You're seeing the groups they're added into, and you start to realize, okay. Some of these tools or access areas they shouldn't really engage in because their role doesn't require it. Now selecting unlinked does not fully remove them from the tool. Vanta does not, do a push, response to allow that to happen. You would have to go into that specific tool and remove them. However, Vanta helps you to document the date and time and the actions performed to remove them from that tool, which I'm gonna show you once we go to the asset section, but just keep that in mind as well. And then the onboarding tab, remember, this only shows up if the employee is marked as terminated. Let me open up this terminated one so you can see it. In this case here, they just have some deprovision accounts. If we select that tab, we see specifically the account that need to be deprovisioned. And then as an admin, once you complete it, on their profile, it's gonna show as complete. And then computers they may not show anything here. Let me choose someone else here. We go to computers tab, which is another reason why that MDM is important. You're able to see which devices they have connected to their profile. Let me click here. Man, I'm just getting all the different changes today. Okay. Alright. If they have a device in it to their profile, you would see that device here. It'll literally show the name on the device, the type of device, the version of OS they have on it, etcetera. Yes. A lot of changes someone has made in this test account. Alright. Now we have our team set up, and we have our groups created to begin those automations. Remember, the automations in the group, you wanna think of it as how do I ensure that my team is compliant, and you're gonna put task there that makes it to where they achieve that level of compliancy based on policy, security trainings, any onboarding and onboarding tasks that you require, and, of course, any deprovisioning of any assets, to specific tools. Now we wanna take a look at the assets tab here because this is where we really want to break down the process that we wanna put in place to manage the assets, layout here. Okay? Because when it comes to most of your audits, really all of your audits, auditors are gonna look for some type of system or process in place where you are checking and pruning privileges to ensure that permissions are given to the right people at the right time. And if any event takes place inside of your organization, that that event has some type of action that is reflected in your assets review section. So let's go to the reviews tab here, and this is gonna list out every single system we have based on their inherent risk score. Okay? And then we're gonna also see any reviews that we have in place. Now this may be bare on your end. Well, let me just speak through the two different types we have here. The first is a scheduled review. Now this is something that definitely I suggest that you create. This is gonna be helpful because it allows an automation to be established to where certain systems are reviewed based on their inherent risk score. So all of your high risk systems, they'll be reviewed quarterly, and then you can set up a, all systems annual schedule review, which are for those lower scoring, inherit risk score, systems. Okay? You can also create a custom one if you will like. Now remember, think of this as your schedule section as an automation. Okay? Once you set it, you basically set it, and then you forget it until you're notified. Okay? So think of it almost like, you know, alright. It's the end of the quarter. We need to go ahead and check these systems, check these permissions, then you're gonna be alerted. That time period is gonna come around. You're gonna complete it. You're good to go. Annual, same case. You wanna have that in place. Okay? Now the one we're gonna create live here is a ad hoc review. So this is for those, you know, any events that take place inside of your organization where maybe you've had a restructure or something, some type of, you know, security event occurred, this is where you wanna create an ad hoc review. We're gonna select create review here. Now from that point, you wanna give the review a name automatically. It'll, you know, add the date, but you can add in or remove this if you would like. We're gonna put just j testing. I don't think I used that variation here yet. Then from that point, you wanna select the key systems that are under question. So which systems are a part of this event that we're checking or this response to a certain thing that we wanna figure out here. Right? It could be all if you wanted to or it can be specific ones. Highly suggest specific ones because your all will be taken care of in your schedule unless the use case is something, you know, very dramatic where you need to check every single one. From that point, let me choose here, and I'm gonna strategically choose some because there's another thing I wanna show you. So that one. Boom. And let me actually do this one too. We've chosen our systems. We're going to create draft fruit, draft review. And then now we see that our systems are in play. Now we got a couple of errors here. Now these errors are appearing because these are specific tools that we don't have integrated inside of Vanta. Okay? So these are vendors that we've listed out in our vendor section that the company uses. However, we don't have a direct integration for Vanta to check who has access to what. Anytime you see this when you're about to perform an access review, you need to address this before you move forward or the access review will not be valid. So in this case here, since we don't have a direct connection to that integration, you wanna select this here and then follow one of these two steps to upload your information inside of Anthem. Now you can do the screenshot method, and this is where the AI will help guide you, you know, by having you upload those key screenshots, and it'll pull that info from the screenshot and then place it, into its proper place inside of Anthem. Or you can download a template and then copy and paste whatever we're requesting in that template. And then once you have completed that process, you'll upload it into Vanta, and then the AI will still pull the info, place it inside that profile. You wanna choose one of these two options in order for you to satisfy this requirement. And then once you have satisfied it, you shouldn't see this error message appear any longer. Now since we, can't do this process live, I'm just gonna move forward so you can see what it looks like, once you have an access review in place. Now what I'm gonna do is bypass the alert that will appear that is addressing these two. Okay? But if you were to see it, do not bypass it. Definitely go back and then satisfy the requirements here before you move forward. We're gonna hit start review. We're gonna ignore those, notifications here. Start that review, and then it's going to run-in the background. You're gonna see the two systems that can sync populate here. Now in this space here, this is where you wanna begin the review. Now this process, remember, the goal here is to ensure and confirm that whoever has access to this tool should have access to it. Now with the AI component inside of Anthem, let's say you had a restructure, maybe you had to lay some people off. One suggestion that I would say before you perform an access review is to go ahead and change their profile to terminated first inside of Vanta. That way, when you perform those access reviews, and let me show you what it looks like in real time, the Vanta AI can recommend, why a specific employee should not have permissions to that specific tool. Okay? So I went inside this specific one. This one doesn't have any insight too. Let me go into the other one real quick here. Hopefully, it does. It did previously. Okay. It does have AI insights, but it's not showing specifically what I wanted you to see. I think they already removed that member. But if that this person was, you know, if one of these individuals were marked as terminated, you'll see the AI recommendation to remove or deny in this specific area because it's going to show you instead of active employee, it's gonna show you that this employee is marked as terminated inside your Vanta account. So the suggestion is to not move forward with that specific employee. In this case, all of these team members are classified as active employees. So in this case, the AI is suggestion suggest suggesting that we approve these specific individuals, because they are active in your system. If anything, maybe check their level of permission to confirm that, you know, maybe there's a step lower that they should be in order for them to function with that tool or etcetera. Okay? The idea here is to make your access review, process smoother and quicker by having the AI run some background checks to confirm that these members are members that should be, using the specific tool. Okay? From that point, you do have to go deeper because there may be a specific scenario at, you know, where for example, maybe all of these individuals are approved. However, Dana should not be in this specific tool because of the fact that she's in a different department now. Right? Then from that point, you can do, like, change roles here, right, and then mark it. And, you know, I might as well talk about this section here. Once you select that, you're gonna see some more context of the AI recommendation. And then from that point, you're gonna choose an option. I can't necessarily do it in the demo environment here, but I just want you to see see how this kinda looks here. And then from that point, if she is changing roles and you need her to be removed from this tool, then you want to create a task in your task tracker to connect with whichever, you know, department or team member that has the capability to adjust her permissions and then move her to a specific tool that she does need to be added to. So let me just show you what it looks like very quickly. If you're using Jira, you simply locate the connection space. You're gonna then choose the project where specific tasks are set up. We're just gonna choose API here. Then from that point, you can choose the issue type, who you want to assign it to. You can make yourself the reporter if you wanted to. I'm sorry. Not yourself. You can make, someone else well, let me take the bet. You can make yourself the reporter if you wanted to. You just need to make sure that you're also inside that tool as well. And then if you know the epic, you can choose the epic, the sprint. And what you're gonna see here is that Vanta automatically creates the task, information for you. So here's the name of the task here, account assets update, Asana. Right? And then from that point, how do I want you to fix this? I want you to go to Asana system, asset settings, and revoke assets for this specific user. Okay? Once you hit create, you're gonna see that task listed here, and you're gonna see a link to where you can access that Jira at any time inside your Vanta account. Now this is the only necessary steps you need to take if you're going to deny change roles a specific user. Now if you happen to go to this list, what you can do is you can mass select and approve a specific group if you want to as well. Okay? This is something that is definitely helpful, especially if you went through the list manually. You took a, you know, good look at it. You realize that everything listed is what should be. You can approve it to completely, satisfy this specific part of your review, and then go back and then go into the next tool. You'll just repeat that process consistently until you complete that entire, review process. Then from that point, you'll see the complete option here. And then once it's completed, it will be listed in your assets review list here as completed. And let me show you what it looks like. Boom. And that is how you perform those access reviews inside of answer. Now I know we're at time, so I gotta wrap up here. Adam, you said, my access tab looks different than yours. Now depending on, if I'm not mistaken, the specific plan you have, you're able to see additional context. I'm kind of, not familiar fully with how each plan is segmented. But depending on your plan and on in this environment as a whole, we have everything from up to enterprise and beyond in in this environment, so you may see some things that are not particularly on your instance. We're working on having plan specific, testing environments now. So, you know, some of these you may not see. Yeah. But I'm glad you called that out, Adam. Yeah. But if you are interested in any of these specific components, definitely hit this, matter of fact, no. Let me do this. I'm gonna share this with you because this is a more direct way just in case you want to connect support team in a different manner. I'm gonna share a link to it into the chat here on how you connect with our support team here. Definitely check that out and, see if they can, loop you into a, you know, account manager to kinda get you deeper into that. No problem at all, Brian. I'm glad this was helpful. Oh, before everyone go, if you don't mind, I'm gonna share this with you. Love to get a quick review from you. I'm gonna share a link in the chat here, if you could. No problem at all, Adam. If you could, love a great review or any type of feedback you have for me, share that here. This is how we build our programs. If you have any ideas for us on how we could create something new that we don't currently offer, by all means, please, please, please share that in that feedback form. We build every single live training based on your feedback, so that will be helpful. Other than that, thank you so much for attending this session. Definitely check out our other sessions, and I look forward to seeing some of you again. Happy, Tuesday, everyone, and thank you again. Thank you again for attending.