> For the complete documentation index, see [llms.txt](https://docs.veza.com/4yItIzMvkpAvMVFAamTf/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.veza.com/4yItIzMvkpAvMVFAamTf/features/access-request.md).

# Access Requests

Access Requests provides an automated, policy-driven workflow for requesting, approving, provisioning, and auditing access.

Access Requests provides a self-service catalog where users request access to applications, databases, and cloud resources, with automated approval workflows and time-limited grants that reduce standing privilege. The catalog is not limited to systems Veza provisions directly: an item can instead create a ServiceNow or Jira ticket, or send a REST, XML, or SQL action to the system that owns the access, so requests for those applications follow the same approval and audit workflow.

Administrators publish requestable items in the Access Catalog: either [Access Profiles](/4yItIzMvkpAvMVFAamTf/features/access-request/manage-profiles.md) (bundles of application entitlements) or [Catalog Definitions](/4yItIzMvkpAvMVFAamTf/features/access-request/manage-catalog-definitions.md) (actions like application provisioning, ServiceNow ticket creation, or custom REST calls). Users browse the catalog, submit requests with a business justification, and approvers review and act on those requests directly from the Access Hub. Once approved, Veza automatically provisions access for a policy-defined duration and revokes it when that duration expires.

For example:

* An engineer requests temporary production database access for a 4-hour debugging session. Access is automatically revoked afterward, with no manual cleanup required.
* A contractor needs Salesforce access for a 3-month engagement. Their manager approves the request, and access expires at the end of the project.
* A new hire in Sales submits a single request for a pre-configured bundle that includes CRM access, email distribution lists, and collaboration tools, all provisioned automatically upon approval.

Every request, approval decision, and revocation is recorded in the request history, which is not editable from Access Hub. Catalog items can be targeted to specific user populations, so requesters see only the access relevant to their role.

For more about Access Requests concepts and terminology, see [Access Requests Glossary](/4yItIzMvkpAvMVFAamTf/glossary/access-requests-glossary.md).

## Key capabilities

* **Self-service Access Catalog**: users browse, search, and request access through the Access Hub. See [Requesting and Managing Access](/4yItIzMvkpAvMVFAamTf/features/access-request/request-manage-access.md).
* **Approval workflows**: single or multi-step approval with configurable approver categories (administrators, managers, App Owners, Access Profile Owners, or [dynamically resolved](/4yItIzMvkpAvMVFAamTf/features/lifecycle-management/profiles/dynamic-approvers.md) based on profile metadata). See [Approving Access Requests](/4yItIzMvkpAvMVFAamTf/features/access-request/approve-access.md).
* **Just-in-time (JIT) access**: time-limited grants that automatically revoke after a configured duration, reducing standing privilege. Duration can be set by the requester or approver within policy-defined limits.
* **Expiration and escalation**: when pending requests aren't acted on in time, policies can automatically reject, approve, or escalate to designated approvers. See [Managing Access Request Policies](/4yItIzMvkpAvMVFAamTf/features/access-request/manage-policies.md).
* **Automated provisioning**: approved requests provision the requested access in the target system, creating an account only where the target system requires one. Access can also be revoked manually once the request is completed, by the requester, the beneficiary, or an approver on the request. The Administrator role does not confer that action on its own.
* **Access Profiles**: bundles of application entitlements published as catalog items. See [Managing Catalog Items](/4yItIzMvkpAvMVFAamTf/features/access-request/manage-profiles.md).
* **Catalog Definitions**: extend the catalog with ServiceNow ticket creation, custom REST calls, and other fulfillment types. See [Managing Catalog Definitions](/4yItIzMvkpAvMVFAamTf/features/access-request/manage-catalog-definitions.md).
* **Request history**: every request, approval decision, and revocation is recorded, attributed, and timestamped. See [Access request history](/4yItIzMvkpAvMVFAamTf/features/access-request/request-history.md).
* **Beneficiary Manager approval workflows**: managers can approve or reject access requests for their direct reports. Whether a manager resolves depends on the identity source. See [Approving Access Requests](/4yItIzMvkpAvMVFAamTf/features/access-request/approve-access.md) and [Beneficiary Manager approvals](/4yItIzMvkpAvMVFAamTf/features/access-request/manage-policies.md#beneficiary-manager-approvals).

For a detailed feature list, see [Access Requests Features](/4yItIzMvkpAvMVFAamTf/features/access-request/features.md).

## How it works

Access Requests grants and revokes access in the [supported target systems](#supported-applications-and-systems) for the user populations that each catalog item targets:

1. **Request**: Users log in to the Access Hub and browse the Access Catalog to find the access they need. They submit a request with a business justification and, if applicable, a desired access duration.
2. **Approval**: Designated approvers review and approve or reject the request. The Access Request Policy associated with the catalog item determines who must approve and in what order. Approvers can include managers, App Owners, Access Profile Owners, administrators, or [dynamically resolved approvers](/4yItIzMvkpAvMVFAamTf/features/lifecycle-management/profiles/dynamic-approvers.md) based on profile metadata.
3. **Provisioning**: Once approved, Veza automatically creates accounts, assigns entitlements, and manages group memberships in the target system. If the policy specifies a time limit, access is automatically revoked when the duration expires. For requests fulfilled through Jira, the expiry clock starts only after an administrator resolves the grant issue; see [Ticket creation with Jira](/4yItIzMvkpAvMVFAamTf/features/access-request/configure-itsm-integration.md#ticket-creation-with-jira). The requester, the beneficiary, and the request's approvers can also revoke the access manually once the request reaches Completed.
4. **Audit**: All actions, such as access requests, approval/rejection actions, and access revocations, are recorded in the request history for compliance and audit purposes.

Access Requests involve some fundamental components that administrators should understand:

* **Admin Console**: The administrative interface for configuring Access Requests, integrations, and system settings. Administrators who also have Access Hub access can switch between the two using the left-right arrows toggle at the bottom of the left navigation.
* **Access Hub**: The user-facing portal where requesters browse the catalog, approvers act on requests, and managers monitor their team's access.
* **Access Catalog**: The searchable catalog of requestable items within Access Hub.
* **Access Profiles**: Bundles of application entitlements published as catalog items. See [Managing Catalog Items](/4yItIzMvkpAvMVFAamTf/features/access-request/manage-profiles.md).
* **Catalog Definitions**: Extend the catalog with additional fulfillment types: application provisioning, ServiceNow tickets, or custom REST calls. See [Managing Catalog Definitions](/4yItIzMvkpAvMVFAamTf/features/access-request/manage-catalog-definitions.md).
* **Access Request Policies**: Define who must approve requests and how long access lasts. See [Managing Access Request Policies](/4yItIzMvkpAvMVFAamTf/features/access-request/manage-policies.md).
* **Access Request Settings**: Global configuration for approval permissions, catalog visibility, and notifications. See [Access Request Settings](/4yItIzMvkpAvMVFAamTf/features/access-request/settings.md).
* **Lifecycle Management Policies**: Define the integrations, conditions, and actions (such as Manage Relationships and Sync Identities) that fulfill approved requests. See [Lifecycle Management Policies](/4yItIzMvkpAvMVFAamTf/features/lifecycle-management/policies-workflows/policies.md).
* **Integrations**: Target applications, such as Active Directory, Okta, and AWS, configured with write-level credentials to enable automated provisioning. See [Lifecycle Management Integrations](/4yItIzMvkpAvMVFAamTf/features/lifecycle-management/integrations.md).
* **Notifications**: Email and Slack notifications for request events. See [Notifications](/4yItIzMvkpAvMVFAamTf/features/access-request/notifications.md).

### Access Request lifecycle

Access Requests follow a defined state machine, with state transitions based on user actions and system decisions. Understanding these states helps users and administrators track request progress and troubleshoot issues.

#### Access Plans

An Access Plan is the set of actions Veza runs to grant or remove the access that a request asks for. Veza creates the plan from the request, and can generate more than one candidate plan for the same target, but only one plan is selected and executed. The actions in the selected plan appear on the **Access Plan** tab of the request. See [Access request history](/4yItIzMvkpAvMVFAamTf/features/access-request/request-history.md#access-plan-tab).

#### Request states

| State                       | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| --------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Initial**                 | The starting state for newly created requests. Access Requests evaluates whether approval is needed.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| **Waiting For Approval**    | The request requires approval from designated approvers. The request remains in this state until all required approvals are obtained or the request is rejected.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| **Needs More Information**  | An approver has requested additional information from the requester. The request remains in this state until the requester responds.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| **Plan Selected**           | An [Access Plan](#access-plans) has been selected and is being executed. This occurs automatically after approval or immediately if no approval is required.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| **Completed**               | The request has been successfully fulfilled. The requested access has been granted or removed. For time-limited access, the request remains in this state until the duration expires.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| **Errored**                 | An error occurred during execution. Details are available in the request history.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| **Rejected**                | The request was denied by an approver. The rejection reason is recorded in the request history.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| **Canceled**                | The requester withdrew the request before completion.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| **JIT Revoked**             | Previously granted time-limited access has been automatically revoked after the specified duration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| **External Running**        | The request has been handed off to an external ITSM system (such as ServiceNow) for processing. The external system drives state transitions via API callbacks.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| **Conflict Pending**        | The request cannot be routed for approval because the current approval step has no eligible approver. Any of the following routes a request here: the beneficiary's manager has no Veza user account; the beneficiary has no manager configured, on a step set to skip inactive approvers; a Dynamic approver, an App Owner, or an Access Profile Owner resolved to no eligible user; no approver category on a multi-category step is routable; or every approver the step resolved is on the [Deny Approver List](/4yItIzMvkpAvMVFAamTf/features/access-request/settings.md#deny-approver-list). The requester and the beneficiary are always excluded from an approver set, so a step that resolves only to them is unroutable. This is a non-terminal state that requires action: an administrator can reassign the request to a different approver (returning it to Waiting For Approval) or cancel it, and the requester can re-request after the policy is corrected. A tenant setting, turned off by default, can instead retry routing on a schedule: **Retry blocked requests** in Access Request Settings. When the condition that stranded the request clears on its own, most often because the approver signed in through SSO for the first time and gained a Veza user, that retry returns the request to Waiting For Approval without an administrator acting. See [Beneficiary Manager approvals](/4yItIzMvkpAvMVFAamTf/features/access-request/manage-policies.md#beneficiary-manager-approvals). |
| **Revoke Selected**         | A revoke has been initiated, either manually or by the just-in-time timer, and is being executed. No external revoke ticket exists yet. This state parallels Plan Selected on the grant side.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| **Revoke External Running** | A revoke ticket has been created in an external ITSM system, and the request is waiting for that ticket to be resolved before access is removed.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |

#### User actions

| Action                           | Definition                                                                                                                                                                                                                                                                                   | State Change                                                                                                                                                        |
| -------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Approve**                      | Action taken by approvers to grant the requested access.                                                                                                                                                                                                                                     | Waiting For Approval → Plan Selected                                                                                                                                |
| **Reject**                       | Action taken by approvers to deny the requested access.                                                                                                                                                                                                                                      | Waiting For Approval or Needs More Information → Rejected                                                                                                           |
| **Cancel**                       | Action taken by the requester, the beneficiary, or an administrator to withdraw a request. Available from four states only.                                                                                                                                                                  | Waiting For Approval, Needs More Information, Plan Selected, or Conflict Pending → Canceled                                                                         |
| **Request for more information** | Action taken by approvers when they need additional details.                                                                                                                                                                                                                                 | Waiting For Approval → Needs More Information                                                                                                                       |
| **Re-request**                   | Action taken by the requester to correct and resubmit a request. Available from Needs More Information, Rejected, Errored, JIT Revoked, and Conflict Pending, and, for ITSM-backed requests, from Revoke External Running.                                                                   | Any of those → Initial                                                                                                                                              |
| **Revoke access**                | Action to terminate previously granted access. Available to the requester, the beneficiary, and the request's approvers, current or past. Not offered at all for [Application Catalog Definitions](/4yItIzMvkpAvMVFAamTf/features/access-request/manage-catalog-definitions.md#application). | Completed → JIT Revoked. For ITSM-backed requests, the request passes through Revoke Selected and Revoke External Running while the external revoke ticket is open. |
| **Reassign approver**            | Action taken by an administrator to reassign a stuck request to a different, non-conflicting approver.                                                                                                                                                                                       | Conflict Pending → Waiting For Approval                                                                                                                             |

A re-request always restarts the approval flow. Approvals already given are discarded and the request returns to the first approval step, because a re-request can raise the requested duration and an approval given for a shorter grant should not carry over to a longer one.

Two gaps in the table are deliberate rather than oversights:

* **An errored request cannot be canceled.** A failed request may hold a partially applied grant, and Cancel changes the state without revoking anything, so canceling would erase the failure signal and leave orphaned access looking like a clean withdrawal. Re-request it instead.
* **Revoke Selected has no recovery action.** A revoke that stalls in this state cannot be canceled or re-requested from the console. Contact Veza support.

#### System decision points

**Is Approval needed?** When a request is created, Access Requests determines if approval is required based on governance policies. If no approval is needed, the request moves directly to Plan Selected.

**Was the Access Plan successful?** After Access Plan execution, Veza determines if all operations have been completed successfully. The request moves to Completed if successful or Errored if unsuccessful.

**Has JIT Duration passed?** For time-limited access, Veza automatically checks if the duration has elapsed. When it has, the request moves from Completed to JIT Revoked. For requests fulfilled through Jira, the duration does not begin counting down until an administrator resolves the grant issue in Jira.

### Example workflow scenarios

**Standard Approval Flow:**

1. User creates access request (Initial)
2. System determines approval is needed (Waiting For Approval)
3. Approvers review and approve the request (Plan Selected)
4. System successfully implements the access (Completed)

**Information Request Flow:**

1. User creates access request (Initial)
2. System determines approval is needed (Waiting For Approval)
3. Approver requests more information (Needs More Information)
4. Requester provides information and resubmits (Waiting For Approval)
5. Approvers review and approve the request (Plan Selected)
6. System successfully implements the access (Completed)

## Navigating Access Requests

The Access Hub provides different views for different user roles and workflows:

### Access Hub navigation structure

* **Catalog** (Menu Expander)
  * **Catalog**: Browse and request access to available applications, Access Profiles, and Catalog Definitions
  * **Requests**: View and manage your submitted access requests
  * **Assigned Requests**: Review and approve requests where you're designated as an approver
* **My Access**: View your current access across all systems (requires manager dashboard feature)
* **My Team**: Managers can view and manage their team's access (requires manager role and appropriate permissions)
* **Access Reviews**: Participate in access certification campaigns (separate from Access Requests)
* **Access Profiles**: View and manage Access Profiles configured for your organization
* **Settings**: Configure Access Hub settings and preferences

{% hint style="info" %}
**Navigation Tip**: The Catalog section has three sub-pages. Use **Catalog** > **Catalog** to browse available access, **Catalog** > **Requests** to view your requests, and **Catalog** > **Assigned Requests** to view requests awaiting your approval.
{% endhint %}

## Supported applications and systems

Access Requests grants and revokes access in identity providers and directories, cloud platforms, productivity and collaboration suites, business applications, developer platforms, databases and data warehouses, self-managed on-premises systems, and custom applications integrated with the [Open Authorization API (OAA)](/4yItIzMvkpAvMVFAamTf/developers/api/oaa.md).

Two tables on this page list every supported integration:

* [Supported target applications](#supported-target-applications): the integrations that Access Requests can provision, the lifecycle management actions each one supports, and the entitlement types each one can grant, such as groups, roles, permission sets, and licenses.
* [Supported identity sources](#supported-identity-sources): the integrations that can serve as an authoritative source of identity, and the entity types each one contributes.

If a system appears in neither table, you can still publish it in the Access Catalog as a [Catalog Definition](/4yItIzMvkpAvMVFAamTf/features/access-request/manage-catalog-definitions.md) that creates a ServiceNow or Jira ticket, or that sends a REST, XML, or SQL action to the system that owns the access.

### Supported target applications

These integrations support user lifecycle management actions such as identity synchronization, entitlement management, and disabling or deactivating accounts:

| Target Application                                                                                                    | Manage Relationships | Sync Identities | Deprovision Identity | Additional Actions                                  | Supported Entitlement Types                                                                                   | Notes                                                                                                                                                                                                                         |
| --------------------------------------------------------------------------------------------------------------------- | :------------------: | :-------------: | :------------------: | --------------------------------------------------- | ------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| [**Active Directory**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/active-directory/provisioning.md)              |           ✅          |        ✅        |           ✅          | Reset Password, Create Entitlement, Delete Identity | ActiveDirectoryGroup                                                                                          | -                                                                                                                                                                                                                             |
| [**Atlassian Cloud**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/atlassian/provisioning.md)                      |           ✅          |        ✅        |           ✅          | Delete Identity                                     | AtlassianCloudAdminGroup                                                                                      | -                                                                                                                                                                                                                             |
| [**AWS SSO**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/aws/provisioning.md)                                    |           ✅          |        ✅        |           ✅          | Create Entitlement                                  | AwsSsoGroup                                                                                                   | -                                                                                                                                                                                                                             |
| [**Azure**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/azure/provisioning.md)                                    |           ✅          |        ✅        |           ✅          | Reset Password, Create Email, Create Entitlement    | AzureADGroup, AzureADRole, ExchangeOnlineDistributionGroup, AzureADLicense                                    | Email management includes mailbox configuration (size limits, quotas, auditing) and client access settings (OWA, ActiveSync, MAPI, POP, IMAP)                                                                                 |
| [**Custom Application (OAA Template)**](/4yItIzMvkpAvMVFAamTf/features/lifecycle-management/integrations/oaa-scim.md) |           ✅          |        ✅        |           ✅          | Delete Identity                                     | ApplicationGroup, ApplicationRole                                                                             | -                                                                                                                                                                                                                             |
| [**Database Application**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/database-application.md)                   |           ✅          |        ✅        |           ❌          | Delete Identity                                     | `OAA.<application type>.Group`, `OAA.<application type>.Role`                                                 | Requires feature enablement. Relationship management depends on configuration: group entitlements require the add and remove group stored procedures, and role entitlements require the add and remove role stored procedures |
| [**Exchange Server**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/exchange-server/provisioning.md)                |           ❌          |        ❌        |           ❌          | Create Email                                        | -                                                                                                             | -                                                                                                                                                                                                                             |
| [**GitHub**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/github/provisioning.md)                                  |           ✅          |        ✅        |           ✅          | Delete Identity                                     | GithubOrganization, GithubTeam                                                                                | -                                                                                                                                                                                                                             |
| [**LDAP**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/ldap/provisioning.md)                                      |           ✅          |        ✅        |           ✅          | Delete Identity                                     | LDAP group                                                                                                    | Includes Red Hat Identity Manager and FreeIPA                                                                                                                                                                                 |
| [**Google Workspace (Google Cloud)**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/google/provisioning.md)         |           ✅          |        ✅        |           ✅          | Delete Identity                                     | GoogleWorkspaceGroup                                                                                          | -                                                                                                                                                                                                                             |
| [**MySQL**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/mysql/provisioning.md)                                    |           ✅          |        ✅        |           ✅          | Delete Identity                                     | MySQLRoleInstance                                                                                             | -                                                                                                                                                                                                                             |
| [**Okta**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/okta/provisioning.md)                                      |           ✅          |        ✅        |           ✅          | Reset Password, Create Entitlement, Delete Identity | OktaGroup                                                                                                     | Supports two deprovision types: SUSPENDED (temporary) and DISABLED (permanent deactivation)                                                                                                                                   |
| [**Oracle Database**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/oracle-database/provisioning.md)                |           ✅          |        ✅        |           ✅          | Delete Identity                                     | OracleDBRole                                                                                                  | -                                                                                                                                                                                                                             |
| [**Oracle Fusion Cloud**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/oracle-fusion-cloud/provisioning.md)        |           ✅          |        ✅        |           ✅          | Delete Identity                                     | OracleRole                                                                                                    | -                                                                                                                                                                                                                             |
| [**Oracle HCM**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/oracle-hcm/provisioning.md)                          |           ❌          |        ✅        |           ❌          | Write Back Email                                    | -                                                                                                             | -                                                                                                                                                                                                                             |
| [**PagerDuty**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/pagerduty/provisioning.md)                            |           ✅          |        ✅        |           ❌          | Delete Identity                                     | PagerDutyTeam                                                                                                 | Platform does not support user deactivation; use Delete Identity instead                                                                                                                                                      |
| [**PostgreSQL**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/postgresql/provisioning.md)                          |           ✅          |        ✅        |           ✅          | Delete Identity                                     | PostgreSQLGroup                                                                                               | -                                                                                                                                                                                                                             |
| [**Salesforce**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/salesforce/provisioning.md)                          |           ✅          |        ✅        |           ✅          | -                                                   | SalesforceGroup, SalesforcePermissionSet, SalesforcePermissionSetGroup, SalesforceProfile, SalesforceUserRole | -                                                                                                                                                                                                                             |
| **SAP ECC**                                                                                                           |           ✅          |        ✅        |           ✅          | -                                                   | SapEccRole                                                                                                    | Manage Relationships supports role assignment only (revocation is not supported)                                                                                                                                              |
| [**SCIM**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/scim/provisioning.md)                                      |           ✅          |        ✅        |           ✅          | Delete Identity                                     | SCIMGroup                                                                                                     | Supports token authentication and OAuth2 client credentials                                                                                                                                                                   |
| [**ServiceNow**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/servicenow/provisioning.md)                          |           ✅          |        ✅        |           ✅          | Update ServiceNow Table                             | ServiceNowGroup, ServiceNowRole                                                                               | Manage Relationships covers directly granted roles only; roles inherited through group membership are not managed                                                                                                             |
| [**Snowflake**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/snowflake/provisioning.md)                            |           ✅          |        ✅        |           ✅          | -                                                   | SnowflakeRole                                                                                                 | -                                                                                                                                                                                                                             |
| [**Splunk Enterprise**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/splunk-enterprise/provisioning.md)            |           ✅          |        ✅        |           ❌          | Delete Identity                                     | SplunkEnterpriseRole                                                                                          | Platform does not support user deactivation; use Delete Identity instead                                                                                                                                                      |
| [**Workday**](/4yItIzMvkpAvMVFAamTf/integrations/integrations/workday/provisioning.md)                                |           ✅          |        ✅        |           ❌          | Write Back Email                                    | WorkdaySecurityGroup                                                                                          | -                                                                                                                                                                                                                             |
| **Veza**                                                                                                              |           ✅          |        ✅        |           ✅          | -                                                   | VezaRoleBinding, VezaAccessProfile, VezaGroup                                                                 | -                                                                                                                                                                                                                             |

### Supported identity sources

These integrations can be used as authoritative sources of identity for policy-based provisioning:

| Identity Source                                                                                       | Supported Entity Types      | Notes                     |
| ----------------------------------------------------------------------------------------------------- | --------------------------- | ------------------------- |
| [Active Directory](/4yItIzMvkpAvMVFAamTf/integrations/integrations/active-directory.md)               | ActiveDirectoryUser         |                           |
| [Beeline](/4yItIzMvkpAvMVFAamTf/integrations/integrations/beeline.md)                                 | CustomHRISEmployee          |                           |
| [Coupa CCW](/4yItIzMvkpAvMVFAamTf/integrations/integrations/coupa-ccw.md)                             | CustomHRISEmployee          |                           |
| [Custom IDP](/4yItIzMvkpAvMVFAamTf/developers/api/oaa/templates/custom-identity-provider-template.md) | CustomIDPUser               |                           |
| [Custom HRIS (OAA)](/4yItIzMvkpAvMVFAamTf/developers/api/oaa/templates/hris-template.md)              | CustomHRISEmployee          |                           |
| [Database HRIS](/4yItIzMvkpAvMVFAamTf/integrations/integrations/database-hris.md)                     | CustomHRISEmployee          |                           |
| [HiBob](/4yItIzMvkpAvMVFAamTf/integrations/integrations/hibob.md)                                     | CustomHRISEmployee          | Supports email write-back |
| [LDAP](/4yItIzMvkpAvMVFAamTf/integrations/integrations/ldap/provisioning.md)                          | LDAP user                   |                           |
| [Ivanti Neurons HR](/4yItIzMvkpAvMVFAamTf/integrations/integrations/ivanti_nurons_hr.md)              | CustomHRISEmployee          |                           |
| [Azure AD](/4yItIzMvkpAvMVFAamTf/integrations/integrations/azure.md)                                  | AzureADUser                 |                           |
| [Google Workspace](/4yItIzMvkpAvMVFAamTf/integrations/integrations/google.md)                         | GoogleWorkspaceUser         |                           |
| [Okta](/4yItIzMvkpAvMVFAamTf/integrations/integrations/okta.md)                                       | OktaUser                    |                           |
| [Oracle HCM](/4yItIzMvkpAvMVFAamTf/integrations/integrations/oracle-hcm.md)                           | OAA.Oracle HCM.HRISEmployee | Supports email write-back |
| [ServiceNow](/4yItIzMvkpAvMVFAamTf/integrations/integrations/servicenow/provisioning.md)              | ServiceNowUser              |                           |
| [UKGPro](/4yItIzMvkpAvMVFAamTf/integrations/integrations/ukgpro.md)                                   | CustomHRISEmployee          |                           |
| [Workday](/4yItIzMvkpAvMVFAamTf/integrations/integrations/workday.md)                                 | WorkdayWorker               | Supports email write-back |

The tables above are maintained as the authoritative list of supported integrations. See [Lifecycle Management Integrations](/4yItIzMvkpAvMVFAamTf/features/lifecycle-management/integrations.md) for integration-specific setup instructions and required permissions.

## Getting started

To enable Access Requests, you must configure SSO authentication, identity provider settings, target application integrations, approval policies, and Access Profiles. The setup involves both platform prerequisites and Access Requests-specific configuration.

For a complete walkthrough, see [Setting Up Access Requests](/4yItIzMvkpAvMVFAamTf/features/access-request/enable-access-requests.md).

## Learning more

The Access Requests documentation is organized to support different user roles and use cases:

| Resource                     | Description                                                                                                           | Link                                                                                                 |
| ---------------------------- | --------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- |
| **Enabling Access Requests** | Initial configuration steps for implementing Access Requests in your environment.                                     | [enable-access-requests.md](/4yItIzMvkpAvMVFAamTf/features/access-request/enable-access-requests.md) |
| **Access Hub Configuration** | Initial configuration steps for the Access Hub, including Global IdP settings.                                        | [configuration.md](/4yItIzMvkpAvMVFAamTf/features/access-hub/configuration.md)                       |
| **Requesting Access**        | Guide for users to request, track, and manage their own access through the self-service Access Catalog.               | [request-manage-access.md](/4yItIzMvkpAvMVFAamTf/features/access-request/request-manage-access.md)   |
| **Approving Requests**       | Guide for approvers to review, approve, reject, and manage access requests assigned to them.                          | [approve-access.md](/4yItIzMvkpAvMVFAamTf/features/access-request/approve-access.md)                 |
| **Access Request Policies**  | Configure approval workflows, JIT access durations, and expiration policies, and other behavior for granular control. | [manage-policies.md](/4yItIzMvkpAvMVFAamTf/features/access-request/manage-policies.md)               |
| **Access Profiles**          | Create and manage bundles of entitlements available for request in the Access Catalog.                                | [manage-profiles.md](/4yItIzMvkpAvMVFAamTf/features/access-request/manage-profiles.md)               |
| **Settings**                 | Configure system-wide settings, including delegation, approval requirements, and Access Catalog visibility.           | [settings.md](/4yItIzMvkpAvMVFAamTf/features/access-request/settings.md)                             |
| **Access request history**   | Reviewing the recorded actions, approvals, and state changes for a request, and the tenant-wide request table.        | [request-history.md](/4yItIzMvkpAvMVFAamTf/features/access-request/request-history.md)               |
| **Notifications**            | Configure Veza Actions to send notifications about access request events and state changes to stakeholders.           | [notifications.md](/4yItIzMvkpAvMVFAamTf/features/access-request/notifications.md)                   |
| **Glossary**                 | Reference for Access Requests terms and definitions.                                                                  | [access-requests-glossary.md](/4yItIzMvkpAvMVFAamTf/glossary/access-requests-glossary.md)            |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.veza.com/4yItIzMvkpAvMVFAamTf/features/access-request.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
