This operator surface turns raw Microsoft Graph access-review exports into a buyer-readable control plane for Entra governance teams: overdue closeouts, self-reviews, auto-approvals, stale application gaps, and the remediation packet needed before the next audit window closes.
| Risk | Owner | Principal | Resource | Message |
|---|---|---|---|---|
| high privileged-role-auto-approved |
Entra Governance | bob@kgtenant.example | Security Administrator | Privileged role decision approved with no recorded reviewer (likely auto-approval). |
| high reviewer-self-review |
Entra Governance | carol@kgtenant.example | Helpdesk Administrator | Reviewer Carol Helpdesk approved or denied their own access. |
| medium instance-overdue |
Entra Governance | — | — | Access review instance closed 14 day(s) ago and still InProgress. |
| medium stale-decision |
Identity Operations | dave.vendor@example.net | Finance Reports | Decision reviewed 70 day(s) ago but never applied. |
| medium decision-overdue |
Identity Operations | farrah.partner@example.org | Power BI Embedded Workspace | Decision pending for Farrah Guest on Power BI Embedded Workspace. |
| info high-risk-principal |
Entra Governance | alice@kgtenant.example | Global Administrator | Privileged role assignment under review (Global Administrator). |
| info high-risk-principal |
Entra Governance | bob@kgtenant.example | Security Administrator | Privileged role assignment under review (Security Administrator). |
| info high-risk-principal |
Entra Governance | carol@kgtenant.example | Helpdesk Administrator | Privileged role assignment under review (Helpdesk Administrator). |
| info high-risk-principal |
Platform Security | gina@kgtenant.example | User Administrator | Privileged role assignment under review (User Administrator). |