Access requests
Access requests provide a documented workflow when a user needs permission for a restricted action or resource.
Submit a request
- Open the restricted action or access-request area.
- Select the requested capability or role change.
- Explain the operational need and expected duration.
- Identify the affected organization, records, or workflow.
- Submit the request.
Request the minimum access required. Do not use access requests to obtain another person’s account or credentials.
Review a request
An authorized reviewer should verify identity, training, job responsibility, segregation of duties, duration, and risk. Approve, reject, or request clarification according to procedure.
Approval may require an electronic signature and should remain tied to the exact request.
After approval
Confirm that the granted permission matches the decision. Time-limited or temporary access should be removed when the work is complete.
Audit and periodic review
Requests and decisions are recorded with actor, time, reason, and affected access where supported. Include access requests in periodic membership and privilege reviews.