Recent searches

in

What is an Access Review?

Last modified: September 10th, 2026

On this page

An Access Review is a CSV file listing everyone with access to your Organization, how they sign in to CloudCannon, and when they were last active. It lets you confirm who currently has access and what kind, and produce evidence for a security audit. Members of the Owners Permission Group, or the Partner Permission Group in a Client Organization, can export one. For more information, please read our documentation on exporting your Access Review.

A screenshot of the Members tab on the Team page under Org Settings shows a list of Team Member cards above the Export access review button.

What the Access Review covers#

An Access Review covers everyone with a Permission Group membership in your Organization, including Team Members who access your content through Site Sharing, and anyone you have invited who has not accepted yet. It does not cover people who reach a Site through Client Sharing, who have no CloudCannon account to list, or API Keys, which belong to your Organization rather than to a person. For more information, please read our documentation on what Client Sharing is, what API Keys are, and sharing a Site with Site Sharing.

An Access Review contains one row for each Permission Group membership, not one row for each person. A Team Member who belongs to five Permission Groups appears on five rows, one per Group, with the same email address each time. Rows for pending Team Members are listed after current ones, and contain less information.

Email Address string#

The email address on the Team Member's CloudCannon account or, for a pending member, the address you sent the invitation to.

User Name string#

The name on the Team Member's CloudCannon account. A name is optional, so this is empty for pending members, who have no account yet, and for anyone who has not set one.

Access Type string#

Organization for someone with access to your whole Organization, or Site for someone with access to a single Site through Site Sharing.

Site Sharing Site ID string#

The numeric ID of the shared Site, the same ID that appears in that Site's CloudCannon URL. Empty on every row where Access Type is Organization.

Site Sharing Site Name string#

The name of the shared Site. Empty on every row where Access Type is Organization.

Permission Group Name string#

The Permission Group whose membership this row records. For more information, please read our documentation on what Permission Groups are.

Date Invited string#

When you sent the invitation. Empty on every current member row, where the equivalent date is in the Date Accepted column.

Date Accepted string#

When the person accepted their invitation and joined this Permission Group. Empty on every pending member row, where the invitation date is in the Date Invited column.

SSO Login boolean#

true when the Team Member signs in to CloudCannon with SSO rather than a password. For more information, please read our documentation on adding SSO/SAML authentication.

MFA Enabled boolean#

true when the Team Member has turned on multi-factor authentication for their account. For more information, please read our documentation on enforcing multi-factor authentication.

Last Active string#

The most recent date CloudCannon recorded activity for the Team Member in this Organization. Empty when there is no recorded activity, and on every pending member row.

Read the SSO Login and MFA Enabled columns on current member rows only. Both columns describe a CloudCannon account, and a pending member has not created one yet, so both columns read false on every pending member row, whichever way that person signs in once they join.

The SSO Login and MFA Enabled columns describe the account as it stands when you run the export, not any particular sign-in. A true value in MFA Enabled means the Team Member has multi-factor authentication turned on now, not that they used it the last time they signed in. To see the method and date of individual sign-ins, please read our documentation on what Login Sessions are.

If the Last Active column is empty#

An empty Last Active cell means CloudCannon has no recorded activity for that Team Member in this Organization. Pending members have no activity to record, so their cells are always empty.

If Last Active is empty on every row, including rows for Team Members you know are active, treat the column as unavailable rather than as evidence that nobody has used your Organization. Contact our support team with your Organization name and the date and time you ran the export.

Related Resources

Open in a new tab