Software Management

Software Compliance Report

Runs periodic access reviews by having managers attest to each direct report's application access, then consolidates the results into an audit-ready record to support compliance requirements.

Software Compliance Report
  • Scopes the review to the right employees using flexible filters such as employee classification, status, location, and more
  • Pulls application access across all in-scope employees
  • Reaches out to managers through their preferred communication channel to request attestation
  • Tracks responses against a configurable deadline with automated reminders
  • Consolidates the collected responses into a structured report
  • Creates e a ticket with the report attached for IT and compliance review

What Software Compliance Report does

Software Compliance Report is Harmony's automated application access review workflow. Running on a weekly schedule, Harmony collects all employees and their current application access, notifies each manager to review and acknowledge or reject their direct reports' application permissions, generates a CSV compliance report from the responses, and creates an IT desk ticket with the results. This gives IT and compliance teams a recurring, evidence-backed record that application access has been reviewed - a critical requirement for many security and compliance frameworks.

Who Software Compliance Report Is For

Persona

IT admins and compliance teams who need to demonstrate that application access is periodically reviewed and certified by the relevant business owners (managers).

Pain point

Access reviews (user access certifications) are a recurring compliance burden - frameworks such as SOC 2, ISO 27001, and internal policies require that employee application access be reviewed periodically and certified by managers. Without automation, this requires manually gathering access lists, emailing managers, chasing responses, and compiling results. Harmony automates the full cycle.

How Software Compliance Report Works

Trigger

A cron schedule fires (default: weekly, Monday at 8 AM UTC). Schedule and timezone are configurable per tenant.

  1. Employee and application enumeration

    The workflow lists all employees and fetches each employee's current application access.

  2. Manager notification

    Harmony sends each manager a notification asking them to review and acknowledge or reject their direct reports' application permissions. Managers have a configurable window to respond (default: 7 days). Reminders are sent every 24 hours up to a maximum of 3 before the deadline.

  3. Response collection

    Manager responses (acknowledge / reject) are collected and tracked per employee-application pair.

  4. CSV report

    A compliance report (compliance_report.csv) is generated from all responses, including the outcome of each review.

Outcome

A ticket titled "Software Compliance Report" is created in the IT desk with the CSV attached, providing a trackable, dated record of the review cycle.

Capabilities

  • Automated access review orchestration - Runs the full manager-review cycle: collect access data → notify managers → collect responses → generate report → create ticket.
  • Manager notifications with deadline - Sends each manager a structured notification with a configurable deadline (default: 7 days from notification), making the review expectation clear.
  • Automated reminders - Sends reminder notifications every 24 hours (configurable) up to a maximum of 3 reminders before the deadline, reducing the need for manual follow-up.
  • 7-day response window - Managers have a full week (168 hours; configurable) to review and submit their responses before the workflow closes the review cycle.
  • CSV compliance report - Generates a structured compliance CSV covering all employee-application-manager review outcomes, suitable for audit evidence.
  • IT desk ticket as audit trail - Creates a dated, trackable IT ticket with the compliance report attached - providing an auditable record of each review cycle.
  • Configurable schedule - Cron schedule and timezone are fully configurable per tenant (default: weekly on Monday).

Main use cases

Weekly SOC 2 Access Certification - A company's SOC 2 Type II requirements mandate that application access be certified by managers on a recurring basis. The workflow runs weekly, notifies all managers to review their direct reports' access, collects responses within the 7-day window, and produces a compliance CSV attached to an IT ticket - creating the recurring certification record required by the audit.

Quarterly Access Review Cycle - IT runs a more thorough access review every quarter rather than weekly. The cron schedule can be changed to quarterly, and the response window and reminder intervals can be adjusted to give managers more time for a deeper review.

Detecting Unauthorized or Excessive Access - During the review, a manager notices an application assigned to a direct report that the employee no longer needs. The manager rejects that access in the review. The rejection is captured in the compliance CSV and creates a record for IT to follow up and remove the access.

Integrations

IntegrationRole in the agent flow
Employee Directory / HRIS (internal)Source of employee list and manager relationships used to route reviews to the correct managers
Application Management API (internal)Source of current application access per employee - defines what each manager is asked to review
Service Desk (internal)IT ticket created with compliance report CSV attached; serves as the auditable record of each review cycle
Notifications system (Slack/Teams)Sends review requests and reminder notifications to managers

FAQ

It's a scheduled Harmony workflow (implemented as a native workflow rather than a YAML template). It runs on a cron schedule, orchestrates the full manager review cycle, and produces an audit-ready report. No user conversation is needed to start it.

Meet more Agents