Core Concepts lessons

Core Concepts · Lesson 4

Access Request Flow

How requests should be routed, approved, and blocked when SoD or privilege risk appears.

Access requests are where policy meets the business. A healthy flow looks like:

  1. User (or manager) selects a role/entitlement from a catalog with clear risk labels.
  2. Policy checks run: SoD, peer group norms, privileged scope, and existing access.
  3. Routing sends low-risk birthright to auto or manager approve; high-risk items to risk/security owners.
  4. Provisioning writes to target systems with an audit record (who, what, why, when).
  5. Expiry or certification hooks ensure temporary access does not become permanent.

Approvers should default to least privilege: approve job-aligned access, deny toxic combinations, and escalate standing privileged requests toward JIT/PAM designs.

Practice with the Access Request Simulator — Approve, Deny, or Escalate each ticket.

Interactive game

Access Request Simulator

Decide Approve, Deny, or Escalate for each request using least privilege and SoD judgment.

Score 0/5·Round 1/5

A new finance analyst needs day-one access aligned to their job.

Requester
Jordan Lee
Role
Finance Analyst
Requested
Finance Analyst business role (GL read, expense submit)
Notes
Manager-approved joiner request; no prior entitlements.

Mark complete

Save progress on this device. Track completion unlocks badges in a later release.