Correct a misrecognised employee in an audit

When you import an access list, autociso reads each row and matches it to an employee in your directory. Matching is automatic, and it is occasionally wrong. This guide shows how to fix a row and what fixing it changes.

Why a row can be matched to the wrong person

Every match is a judgement made from two pieces of evidence: the name and the email address on the row. An exact email decides the match outright — an address belongs to one person. A name does not.

So the failures cluster in one place: rows where the email did not come through. Uploaded images are read by OCR, which sometimes garbles a name or loses the email entirely. A row that reads only Sergey cannot distinguish two employees who share that first name — and if one of them has left the company, matching a live account to the departed employee is exactly the kind of error an access review exists to catch.

autociso does not guess in that situation. When several employees match a name and no email settles it, the row is flagged Needs review rather than attributed to whoever happens to look closest.

Read the Confidence column

Open Access Audit, select an import, and choose the Employees tab. The Confidence column tells you how the match was decided:

ConfidenceMeaningAction
Needs reviewSeveral employees match this name and no email settled it. Nothing was applied.Confirm the right person.
ConfirmedA person set this match by hand.None — it overrides automatic matching.
No employeeA person reviewed this row and decided it is nobody in your directory.None.
A percentage (e.g. 100%)Matched automatically.Spot-check low percentages.

A warning icon (⚠) next to a name in the Employee column means the same thing: Several employees match this name. Confirm the right one.

Compare the Detected As column — the raw name and email read from your file — against the Employee column, which is who autociso matched it to. When those disagree, correct the row.

Correct a row

You need the Owner or Manager role.

  1. Open Access Audit and select the import.
  2. Choose the Employees tab.
  3. Find the row whose Employee is wrong.
  4. Select the pencil icon (Correct match) next to the employee name.
  5. Pick the right person from Select employee, then select the check mark.

You will see Match updated, and the Confidence column changes to Confirmed.

Confirming the person a Needs review row already suggests is worth doing even when the suggestion looks right: it is what records the decision, settles the row, and applies the access the suggestion only proposed.

When the row is nobody in your directory

Occasionally a row does not correspond to any employee — for example, a name that OCR recovered so poorly it is unrecognisable. Clear the selection in Select employee and save. The row keeps its detected name for the record but is attributed to no one, and no access is recorded for it. Its Confidence reads No employee, which is a decision you made, not an unprocessed row.

What changes when you correct a row

Correcting a match is not a display change. It moves the underlying access record:

  • The employee who was matched by mistake loses the access this import gave them for this asset. Access added by hand or established by a different import is not affected.
  • The employee you selected gains that access, with the role from the imported row.
  • The change is recorded in the audit trail with who made it and when.

This matters for the reports built on top of that data. Until you correct the row, Access Inventory, the access graph, and CISO reports all describe the wrong person as holding the access — so a correction fixes the finding, not just the table.

Re-running the import will not overwrite a corrected row. Your decision stands.

Reduce misrecognition at the source

The single most effective thing you can do is make sure email addresses are visible in what you upload. The email is what carries a match; a screenshot cropped to names alone leaves matching with the weakest possible evidence.

  • Include the email column in the capture, and keep it legible — avoid scaled-down or low-contrast screenshots.
  • Prefer a CSV export over a screenshot when the system offers one. CSV is read as text, with no OCR step to damage it.
  • Keep employee records complete. Matching also checks email aliases, so recording a person’s alternative addresses lets rows match on any of them.

See AI Provider Selection for how uploads are read and what leaves your deployment.

Last reviewed: 2026-07-22

Was this page helpful?

Esc