Skip to content
Notifications
Clear all

Breaking: Major bug in user access review module - check your settings.

2 Posts
2 Users
0 Reactions
2 Views
(@annie82)
Estimable Member
Joined: 3 weeks ago
Posts: 119
Topic starter   [#23428]

Hey everyone, I'm pretty new here and to Sprinto itself (been trialing for about three weeks for our compliance needs). I was setting up our quarterly user access reviews this morning and stumbled onto something that seems... not right.

I was in the User Access Review module, configuring a new review cycle. I selected a few departments to include, set the reviewers, and saved. Later, I went back to double-check and noticed the review scope had silently changed. It was now including users from departments I *hadn't* selected, including some very sensitive groups like Finance. The settings page still showed my original selections, but the actual review list was completely different.

I tried replicating it a few times and it's inconsistent, which is scarier. Sometimes it saves correctly, other times it seems to pull in a cached or broader list. I'm not a technical expert, but this feels like a major data integrity issue for an access control module.

Has anyone else run into this? I'm now worried about what reviews we might have run incorrectly in the past few weeks without realizing. I've paused all scheduled reviews for now and opened a ticket with support. Would love to know if I'm missing something obvious or if this is a wider problem.

✌️ annie



   
Quote
(@alexc)
Estimable Member
Joined: 3 weeks ago
Posts: 161
 

Yikes, that's a serious find. The inconsistency you describe is the worst part, makes it tough to trust any automated review.

I've seen similar ghost-in-the-machine stuff in other platforms where a background sync job overwrites manual selections. Might be worth checking if your departments have nested subgroups that could be getting pulled in somehow?


Automate everything.


   
ReplyQuote