Treat revocation as a specific access decision
A review can end because the task is complete, the scope changes or access is no longer appropriate. In each case, the application action needs a specific subject: which grant, in which organization, should stop allowing future access?
RiskSensai’s review access workflow supports explicit revocation under the existing authorization boundary. It is not a command to delete every file a recipient may have seen. The platform’s security information distinguishes controlled access from guarantees about information already disclosed.1
Before taking action, identify the sharing record. A recipient label helps describe the intended person, but the current link mechanism is a bearer grant rather than authentication of that named person. Keep that distinction visible when evaluating what access may have occurred.
Find the correct grant
Open the advisor access workspace in the relevant organization and locate the grant. Review its recipient description, evidence scope, creation context and expiry where shown. Do not choose a record solely because the recipient’s name resembles the one in your notes.
An organization may have multiple grants for different periods or purposes. Revoking one does not automatically prove that every other access route is closed. Check the relevant records and, where needed, ask the organization owner to review any separate grants.
Existing role requirements remain in effect. If you cannot revoke the record, do not use another account’s credentials or attempt to change a grant belonging to another organization. Resolve the legitimate authority question with the owner.
Understand what will stop
Revocation prevents future use through the revoked grant. That is valuable, particularly when a recipient has an existing review session: a previously usable session should not remain an authorization to keep reading after the grant is revoked.
It does not necessarily prevent the recipient from accessing information through a separately authorized membership or another valid grant. The action is specific to the grant you revoke. Think in terms of access paths, not merely people’s names.
| Boundary | What revocation means |
|---|---|
| Future requests through the selected grant | Access is no longer authorized |
| Another independent valid grant | Requires its own review |
| A file already downloaded | The application cannot recall the recipient’s copy |
| Organization evidence itself | The source record is not erased by revoking a recipient grant |
This distinction helps you make an accurate statement to colleagues after the action.
Use the explicit action and confirm the saved state
Choose the revocation action for the reviewed grant and complete any confirmation presented by the interface. Wait for the response and inspect the saved grant status. A visible confirmation is more reliable than assuming a closed dialog means the operation completed.
If the response is uncertain, check the grant state before repeating the action or creating a replacement grant. Preserve the error or safe reference for investigation. An ambiguous response should be reported as ambiguous until the saved state is established.
Do not use an actual customer’s link as an informal security probe. Where access verification is needed, use an approved synthetic record or coordinate an appropriate check with the recipient. Avoid turning an access review into an unauthorized attempt to inspect another organization’s data.
Verify proportionately
The first check is that the correct record is marked revoked. For a controlled test, an authorized reviewer can verify that a new request through the formerly usable synthetic link is denied. An existing recipient session should not override the revocation boundary.
The absence of a successful download after revocation does not prove that the recipient never downloaded the material earlier. Keep your conclusion narrow: future access through this grant has ended. Historical disclosure and local copies require separate consideration.
If you discover another active grant, review its purpose and authority before taking additional action. Do not revoke unrelated access simply because you are closing one review.
Worked example: a review ends early
Suppose an advisor’s review was expected to run for 14 days, but the organization decides after five days to pause the work. The owner locates the relevant grant, confirms that it allowed file access and revokes it.
A useful internal note would state:
The selected review grant is revoked. Future access through that grant has ended. The recipient may retain material already downloaded; the agreed handling of those copies needs a separate confirmation.
This note is more accurate than “all shared data has been deleted.” It also identifies a next action: communicate with the recipient about previously obtained material when the applicable agreement or policy requires it.
Communicate without overstating identity
Tell the intended recipient that the access period has ended and explain any relevant next step. Because bearer links can be forwarded, the application record alone does not establish exactly who possessed a copy of the link or every downloaded file.
Where identity or contractual controls are important, use the organization’s approved process for confirmation. Do not manufacture a receipt claiming that all recipients destroyed every copy. The platform’s privacy and review information should be read alongside the organization’s actual agreements.23
Revocation also does not cancel an advisor engagement automatically or resolve a commercial dispute. Access and professional scope are separate matters. Agree any changes to ongoing work through the appropriate human process.
Close the access review with a clear record
Record the grant you reviewed, why access ended, the observed saved status and any remaining follow-up. Avoid placing bearer tokens or unnecessary sensitive file contents in that note. A safe identifier and relevant time can help support investigate without creating a new disclosure.
If the task later resumes, review a new sharing decision rather than assuming the old scope remains appropriate. Evidence access can include later additions during a grant’s lifetime, and the organization’s records may have changed while the work was paused.
Revocation is complete when the selected future-access path is closed and the people responsible understand the remaining limits. It is a useful operational control, but it is not a claim of data erasure, verified recipient identity or recovery of every disclosed copy.
Sources and references
-
RiskSensai. RiskSensai Security. Describes current evidence and access-control limits. ↩
-
RiskSensai. RiskSensai Privacy Policy. Provides the published data-handling policy. ↩
-
RiskSensai. Request a Trust Readiness Review. Explains working-brief preparation and matching limits. ↩

