Overview

The Netlify integration reviews who has access to your Netlify team(s) — the member roster, names, and roles — for user access reviews. LowerPlane uses read-only access via a Netlify personal access token and does not read or modify your sites, deploys, or configuration.
LowerPlane matches each member to a person in your HR directory using their email, so offboarding checks work. Netlify’s member API does not expose per-user MFA, so there is no MFA check.

Prerequisites

You need team owner/admin access to your Netlify team. If your team enforces SSO, grant the token access to the team when you create it (personal access tokens are denied SSO teams by default).

How to Get Your Token

1

Open personal access tokens

In Netlify, go to User settings → Applications → Personal access tokens.
2

Create a new token

Click New access token, give it a descriptive name (e.g. LowerPlane access review), and set an expiry. If prompted for SSO teams, grant access to the team you want reviewed.
3

Copy the token

Copy the token immediately — Netlify shows it only once.

Connecting in LowerPlane

  1. Go to Settings > Integrations in LowerPlane.
  2. Find Netlify under Hosting Providers.
  3. Paste your Access Token.
  4. Click Connect.

What LowerPlane Checks

User identified

Confirms each Netlify member resolves to a named person, not an anonymous or shared account.

Offboarded access removed

Flags Netlify access still active for an employee who has been offboarded in your HR directory.

Access valid

Verifies each member maps to a current employee in your HR directory whose access has been reviewed.
Admin roles come from the Netlify team role — a member with the Owner role is treated as an admin.