Who can do what, and what to take away
BetaAccess piles up. People keep admin after the task that needed it, leave without their keys being revoked, or stop signing in while their account stays open. The access review reads the workspace as it is now: who holds owner or admin, who signs in with only a password, who has gone quiet, and which credentials are idle, outlived their owner or never expire. Each finding names the change that fixes it.
Where to find it
Under Access review in the workspace sidebar, or with tilldev access review. Owners and admins can read it, including someone holding time-boxed admin. It’s worked out each time you open it, so a fix shows up straight away.
The top of the page counts members, owners, admins, people without an authenticator and live credentials by kind.
What it looks for
| Check | Raised when | Level | Fix |
|---|---|---|---|
authz-admin-no-mfa | An owner or admin has no authenticator for sign-in. | high; low once the workspace requires a second factor | Ask them to add an authenticator on their Profile page, or require two-factor authentication for everyone. |
authz-mfa-not-required | The workspace lets members sign in with only a password. | medium | Turn on “Require two-factor authentication” in the workspace settings. |
authz-stale-admin | An owner or admin hasn’t been active for 30 days. | high for an owner, medium for an admin | Move them to developer and let them ask for time-boxed admin when they need it. |
authz-dormant-member | A developer or viewer hasn’t been active for 90 days. | low | Remove them; inviting them again takes a minute. |
authz-admin-heavy | More than half of a workspace of 4 or more people are owners or admins. | low | Keep a few standing admins and move the rest to developer with time-boxed admin. |
authz-sole-owner | There is one owner and at least one other member. | low | Make a second, trusted person an owner. |
authz-self-approval | Someone may start time-boxed admin without anyone approving. | low | Switch them to peer approval unless they need admin at once, for example on call. |
authz-orphaned-credential | A credential was made by, or acts as, someone who is no longer a member. | high | Revoke it, and mint a new one owned by someone still here if it is needed. |
authz-unused-credential | A credential hasn’t been used for 90 days, or was never used in the 30 days since it was made. | medium when it can write or administer, low otherwise | Revoke it. |
authz-unexpiring-credential | A credential that can write or administer has no expiry date. | low | Replace it with one that expires. |
A member counts as active when they sign in or their session renews. Someone with no record of activity counts from the day they joined. A second factor means an authenticator added on the Profile page; a passkey used only for approvals isn’t counted, and sign-in through your company’s identity provider isn’t visible to the review.
Which credentials it covers
- API key (
api_key) - TillSecrets service token (
secrets_token) - TillSecrets agent token (
secrets_agent) - TillForge access token (
forge_token) - TillForge SSH key or deploy token (
forge_key) - TillCache token (
cache_token) - TillArk token (
ark_token) - TillNotary token (
notary_token) - TillShield edge key (
edge_key)
Revoked and expired credentials are left out. A credential counts as used when a request presents it.
Fixing a finding
Each fix is an ordinary request to the API, the same one the rest of the dashboard sends, so it follows the same rules: only an owner can demote an owner, the last owner can’t be removed, and making someone eligible for time-boxed admin needs an approval. In the dashboard, revoking or removing asks you to confirm first; in the CLI, add --yes.
tilldev access review # inventory, then findings, most serious first
tilldev access review --level high
tilldev access review --fail-on high --json # exit 1 if anything high is open
tilldev access review fix authz-stale-admin:member:5b0c… # every step, in order
tilldev access review fix authz-stale-admin:member:5b0c… --step 1 # only the first
tilldev access review fix authz-orphaned-credential:api_key:9f1e… --yes # revokes and removals ask firstKeeping something on purpose
A break-glass owner who rarely signs in, or a deploy key that runs once a quarter, can be right. Accept the finding with a reason of at least 10 characters, for 90 days by default and 366 at most. It moves to Accepted with the reason and who accepted it, and returns to the list when that time runs out. Accepting it again renews it.
- Accepting needs a standing owner or admin and an approval; time-boxed admin can’t accept anything.
- Only an owner can accept a high finding.
- Nobody can accept a finding about themselves.
tilldev access review accept authz-sole-owner:workspace \
--reason "two founders; the second is on leave until March" --days 90
tilldev access review accepted
tilldev access review unaccept 3c2a…How quiet is too quiet
| Setting | Default | Range |
|---|---|---|
admin_days | 30 days | 7–365 days |
member_days | 90 days | 14–730 days |
credential_days | 90 days | 14–730 days |
tilldev access review settings # show
tilldev access review settings --admin-days 14 --credential-days 60The record
Every fix is recorded by the endpoint it calls. Role changes and removals from the workspace, changes to the two-factor requirement, accepted findings, removed acceptances and threshold changes are in the workspace audit log and the security event stream. Moving someone into owner or admin raises a high finding in TillTell.
From the API
The endpoints are under Access in the API reference. They take a signed-in session; an API key gets 401.
curl -s https://tilldev.dev/api/access/review -H "authorization: Bearer $SESSION"
# Each finding carries the requests that fix it
# { "id": "authz-stale-admin:member:5b0c…", "level": "medium", "fixes": [
# { "label": "Move to developer", "method": "PATCH", "path": "/api/team/5b0c…", "body": { "role": "developer" } },
# { "label": "Let them ask for admin", "method": "PUT", "path": "/api/access/eligibility/5b0c…", "body": { "max_minutes": 60, "approval": "peer" } } ] }tilldev access review --fail-on high on a schedule if you want one. Activity is recorded when a session is made or renewed, so it is accurate to about an hour.