Skip to content

Access Review for supervisors

Access Review is the cross-operator view of who accessed tip data, when, and why: one row per operator, with a drill-down into the exact events behind it.

Where a single tip’s audit view (see Reading a tip: the audited decrypt) shows everyone who has touched that one case, Access Review flips the angle: pick a time window and see every operator’s activity across every tip, side by side.

For each operator in the window, the table shows four counts:

  • Viewed: tips opened, summaries expanded, the inbox opened.
  • Decrypted: sealed content actually opened for reading.
  • Exports: data pulled out for reporting or legal disclosure.
  • Denied: access attempts the system blocked.

Alongside the table, a summary strip totals decrypts, exports, and denials for the whole program, and names whoever was most active in the window.

Access Review: filters by operator and period, and the summary counts.

Access Review, filtered to the last 90 days.

  1. Open Access Review from the admin section.
  2. Set a date range: the last 7, 30, or 90 days, or a custom span.
  3. Optionally narrow to one operator by name.
  4. Optionally filter to one activity type: viewed, decrypted, exports, or denied.

The table re-sorts by total activity, busiest operator first.

Select any row to expand it into that operator’s individual events for the window: what happened, roughly when, and — where one was recorded — a stated reason such as opening a tip, printing it, or looking up its location.

Long lists load in pages rather than all at once; a Load more control appears when there’s more to see.

An operator whose total is well above the rest of the team’s for that window gets a flag next to their name. It’s a statistical comparison, not a conclusion: a busy week, a reassignment, or a single large case can all produce one honestly. Use the event log underneath to check the individual reasons before treating it as anything more than a prompt to look closer.

Reporter activity is never logged, so it never appears in Access Review. This surface records what operators and the system did, not what a tipster wrote or did on their end.

Why the trail can’t be cleaned up afterward

Section titled “Why the trail can’t be cleaned up afterward”

Every access row is written before the record it describes is even shown: a failed or denied attempt still leaves one. Once written, no operator role can edit or remove a row. That includes running an access review itself: opening this screen is its own logged event, so a supervisor’s own reviewing is part of the same accountable trail.

Access Review needs the audit-review permission, held by program admins and system admins by default. Anyone else who opens the page sees a plain notice instead of the screen: never a broken page, never partial data. If you need this view and don’t have it, ask your program admin.

The same accountability guarantee is described for reporters, in their own words, on Operator accountability.