Access requests are where policy meets the business. A healthy flow looks like:
- User (or manager) selects a role/entitlement from a catalog with clear risk labels.
- Policy checks run: SoD, peer group norms, privileged scope, and existing access.
- Routing sends low-risk birthright to auto or manager approve; high-risk items to risk/security owners.
- Provisioning writes to target systems with an audit record (who, what, why, when).
- Expiry or certification hooks ensure temporary access does not become permanent.
Approvers should default to least privilege: approve job-aligned access, deny toxic combinations, and escalate standing privileged requests toward JIT/PAM designs.
Practice with the Access Request Simulator — Approve, Deny, or Escalate each ticket.