Access Requests

The self-service front door for requesting access to a system — separate from, but feeding into, Access Reviews.

Before access to something gets periodically re-certified (see Access Reviews & Segregation of Duties), it has to be requested and granted in the first place — that's what this page covers. The two are connected: once an access request is fully activated, it's what starts showing up as something to periodically re-certify.

Requesting access

From the portal (or the internal Access Requests page), click New Request and fill in the request type (new, modify, or remove access), the system or application, the access level or role you need, how long you need it (a fixed duration or permanent), and a required business justification. Submitting starts the approval flow.

Approval

By default, a request routes to the requester's manager. If they have no manager on file, or your tenant has manager approval switched off for this flow, it auto-approves instead — with a system note explaining why. If the request would conflict with an active Segregation of Duties rule, approval is blocked until the approver enters a documented override justification.

If your tenant requires a second sign-off, an approved request moves to a genuinely separate Pending Secondary Approval stage — routed to the first approver's own manager, not back to the same person. That second approver sees their own dedicated approve/reject screen with their own comments field, tracked apart from the first-tier decision. If the first approver has no manager on record to escalate to, the request is approved at the first tier instead of getting stuck.

Provisioning and activation

Approval doesn't grant the access by itself — someone still has to click Mark as Provisioned once the account or role has actually been set up in the target system, and then Activate & Schedule Review to confirm it's live. That activation step is what schedules the request's first periodic recertification.

Revoking access

An admin can revoke active access at any time with a reason; an employee can also self-revoke their own access from the portal once they no longer need it.

Example

A contractor needs 90 days of read-only access to a reporting tool. They submit a request with that duration and a justification; their manager approves it. IT provisions the account and marks it provisioned, then activates it — which schedules the access for its first periodic review, so it doesn't just sit there indefinitely once the 90 days are up without anyone checking.