Skip to main content

Access Requests

Access requests are the core break-glass workflow. They provide a consistent, auditable way to request emergency access to a credential.

Create a request

  1. Go to Requests.
  2. Click New Request.
  3. Select a credential.
  4. Enter a Reason.
  5. Optionally add an Incident Reference (for example, INC-1234).
  6. Click Submit Request.

A RequestCreated audit event is recorded.

Monitor active emergencies

The Requests page highlights Active Emergencies when there are approved requests that have not yet expired.

This gives responders and auditors a quick view of who currently has time-bounded emergency access, and when it expires.

Approve or deny a request

Only users with the Approver role (or Admin) can approve or deny.

  1. Open the request detail page.
  2. Choose an access duration:
  • 1 hour
  • 4 hours
  • 24 hours
  1. Click Approve or Deny.

Approvals set an expiry time. After approval:

  • The request appears as Active until the expiry time.
  • After expiry, it appears as Expired.

Close a request

Only the requester (or an admin) can close an approved request.

  1. Open the request detail page.
  2. Fill in What did you do? (post-use notes).
  3. Optionally check Credential rotated after use.
  4. Click Close Request.

Closing a request writes a RequestClosed audit event.

Notifications

If SMTP is configured, AccessLedger can send:

  • Request created notifications to approvers and admins
  • Request approved/denied notifications to the requester (and admins)
  • Request closed notifications to the approver (and admins)
  • Expiry reminders based on the organization notification settings

See Notification Settings.