Internal Tool Access Request
Access provisioned with documented approval chain. Requestor notified with onboarding resources. Audit log entry created. 90-day review scheduled for sensitive tools.
Before you start
- Tool catalog with documented owners and access policies
- Approval workflow per tool tier (low/medium/high sensitivity)
- SSO and provisioning automation where possible
- Employee's request (tool, role/permission level, reason)
- Employee's current role and team
- Tool's access policy (who can approve, what level, what review)
The steps
- Validate request basics — Confirm the employee is active, the requested tool exists, and the requested role/permission level is documented. Reject malformed requests with a friendly note explaining what's needed.
- Check the access policy — Pull the tool's access policy: who can approve, what permission levels exist, any prerequisites (training, NDA, certification). Determine the right approver chain.
- Route for approval — Send approval request to: line manager (always), tool owner (for medium-sensitivity), and security lead (for high-sensitivity). Include: requestor, role, permission level, reason. Set 2-business-day SLA on response.
- Provision access on approval — When all approvers sign off, provision access via the identity provider. For SSO-enabled tools, this is automated. For non-SSO, manually create the account with the documented permission level. Send credentials via secure channel only.
- Notify requestor and document — Send the requestor confirmation: tool, level, how to access, any onboarding resources. Log: requestor, tool, approval chain, timestamps. This is the audit trail for SOC 2 / similar compliance.
- Schedule access review — For medium/high-sensitivity tools, schedule a 90-day access review: is the access still needed? Has role changed? Quarterly re-review prevents access creep.
If it goes wrong
Access creep — employees retain access to tools they no longer need
Quarterly access review with auto-revocation if not confirmed needed. Make 'do you still need this?' the default question, not the exception.
Approver bottleneck (line manager OOO, tool owner unresponsive)
Documented backup approvers. After 2 business days no response, auto-route to backup. Don't let single-person availability block the org.
High-sensitivity access granted without security review
Hard-gate in the workflow: high-sensitivity tools require security approver in the chain. Don't allow override.
All OpenLabor playbooks