Help

You can run your first review in under five minutes with the sample data. Email [email protected] for anything else, with the review ID from the review page.

Quick start

1. Name the system

After signup you land on /start. Enter the system ("GitHub org", "QuickBooks"), a period label ("Q3 2026"), a due date, and one or two plain lines for reviewers: what the entitlements mean and what "Revoke" leads to.

2. Import rows

Paste a CSV or upload the file. The mapper asks which column is the user (email or username), the entitlement (role, group or permission), and the reviewer's email. Description, last login, manager and notes are optional but make reviewers faster. Rows without a reviewer are assigned to you. Use sample data loads 40 clearly labeled rows for a fictional company.

3. Check the split

The preview shows "3 reviewers, 40 rows". Fix a wrong reviewer email now; after opening, every change is recorded as an event.

4. Open and send links

Each reviewer gets a magic link. With a verified email and SMTP configured, we send it with a plain explanation of who is asking and why. Every link is also copyable from the Reviewers page.

5. What reviewers see

A phone-friendly page with only their rows. Per row: Keep, Revoke or Don't know, plus an optional comment. "Keep all remaining" requires a typed justification and is recorded as a bulk decision. They can delegate to another email. Submitting locks the campaign; you can reopen it.

6. Reminders

Nothing to configure. Non-submitters hear from us seven days before the due date, two days before, on the day, then every three days overdue, up to four times. You get a daily digest while anything is open. Email invites, reminders and the digest are included from the Starter plan; on Free you copy the links.

7. Act on revocations

The dashboard lists completion, decisions by type, and every Revoke. Make the change in the source system yourself, then mark the row actioned with a date and note. That is the loop the auditor asks about.

8. Close and download the pack

Closing generates the pack: cover, method statement, reviewer roster with timestamps and IP, every row and decision, the revocation follow-through table, exceptions (Don't know, delegated, bulk-approved), and an integrity page with the PDF's sha256, chain head and verify URL. JSON is on Pro. Anyone can paste the hash at /verify. To see one, start free, click "Use sample data", decide a few rows through a reviewer link and close the review; it takes about four minutes and the pack is labeled as sample data.

9. Share with your auditor

On Pro, create a read-only share link with an expiry and revoke it when the audit ends.

10. Next quarter

Open a new review on the same system and the pack compares it with the previous one: new users, removed users, changed entitlements.

Accounts and team

Signing up creates an account (the tenant) and makes you its owner. Owners and admins can invite teammates from Team within the plan's seat limit; an invitation is a link that expires after seven days and can be used once. Roles: owner manages billing and roles, admin manages the team and can delete review data, member runs reviews.

Verify your email address to unlock email to reviewers. Everything else, including copy-link invites and the evidence pack, works before verification.

Verifying a hash

Go to Verify and paste a hash: the SHA-256 of a pack PDF, the body hash printed on its integrity page, or any event hash from the pack's event history. The page reports whether it exists, its position in the chain and when it was recorded. No account is needed and nothing about the content is revealed.

To compute a file's SHA-256: sha256sum pack.pdf on Linux, shasum -a 256 pack.pdf on macOS, Get-FileHash pack.pdf in PowerShell.

Your data

Imported rows, decisions and reviewer records of a closed review are kept for 12, 24 or 36 months (your choice on the Reviews page; default 24), then deleted by a daily job. Evidence packs are kept. "Delete review data" on a review hard-deletes its rows, campaigns, packs and share links immediately; the event history keeps the hashes. To delete your account, email support from the owner's address: rows and uploads are removed immediately and packs are purged after 30 days unless you downloaded them.