Access requests
In Data Access, an access request is automatically generated to ensure proper authorization when users interact with the entities that they do not own, or when they request access on data objects. Access requests ensure that data owners stay in control of who can access their entities, giving them full visibility and control over data sharing decisions.
When access requests are generated
Access requests are automated by-products of your governance actions. They are generated in the following scenarios.
| Scenario | Description |
|---|---|
| Adding unowned data objects | When you add a data object that you do not own to your access control, an access request is generated. The owner of the data object must approve the request before their data is added to your access control. |
| Adding unowned access controls | When you add an access control that you do not own to the What component of your access control, an access request is generated. The owner of the access control must approve the request before their access control is added to your access control. |
| Requesting access from an asset |
If you are granted on-request access in an access control, a preapproved access request is generated when you request access from an asset that is linked to the access control. An on-request access means that you are automatically granted access for a predefined duration (for example, 14 days), after which the access is revoked. |
Viewing access requests
To view access requests, on the Data Access landing page, in the left pane, click Access requests. The Access requests page contains the access requests that you made and the access requests that are assigned to you. The page also contains the access requests in which you are mentioned in a comment.
You can view all access requests only if you have a global role with the Data Access > View All Access And Usage or Data Access > Manage All Access global permission, for example, the Data Access Observer or Data Access Manager global role.
How access requests are grouped
When you add multiple unowned data objects to your access control, one combined access request is generated, even if those data objects have different owners. However, when you add multiple unowned access controls to your access control, a separate access request is generated for each access control, unless they share the same owners.
The "Access requests" page
The Access requests page contains the following information.
| Column | Description |
|---|---|
| Access request | The ID of the access request, shown as a clickable link that opens the access request page. |
| Requested access |
The data objects or the access controls (entities) for which the access is requested. |
| Assignees |
The users who are responsible for implementing or closing the request. These are the owners of the requested entities. |
| Requester | The user who initiated the access request. |
| Created on | The date and time when the access request was generated. |
| Status |
The status of the access request. You can use the Status filter to narrow the list to one or more specific statuses. |
Statuses of access requests
An access request can have one of the following statuses.
| Status | Description |
|---|---|
| Awaiting approval |
The request is awaiting approval in a custom workflow. This status appears only if a custom workflow is configured for access requests. Otherwise, this step is skipped and the request moves directly to the Awaiting implementation status. |
| Awaiting implementation |
The request is waiting for the responsible owner to implement access in the target data source. |
| Implemented |
Access to all requested entities is implemented in the target data source. |
| Partially implemented |
Access to some, but not all, requested entities is implemented in the target data source. |
| Rejected |
No access was implemented in the target data source before the request was closed. |
| Canceled |
The requester (or an authorized user) canceled the request before access was implemented. |
The access request page
The access request page opens when you click an access request ID on the Access requests page. It contains details to help you decide whether to implement or close the request.
The "What access is granted"section
The What access is granted section on the access request page contains the following information.
| Field | Description |
|---|---|
| Access requested on |
The data objects or the access controls (entities) for which access is requested. These are the entities that a user who does not own them added to an access control. |
| Access requested for |
The access control from which the access request originated. This is the access control to which the user added the entities, generating the access request. |
| Access requested until |
The date and time when the access, if granted, expires. For data objects, the default value is Unlimited. For access controls, the date and time is set by the user who added them to the access control. |
| Purpose | System-generated information about the origin of the access request. |
The Implementation section
The Implementation section on the access request page contains the following information.
| Column | Description |
|---|---|
| Data object (or Access control) |
The data objects or access controls for which access is requested. |
| Permissions | The permissions that are associated with the data objects. |
| All owners | The identities that own the requested entities. These are the users who are tasked with reviewing the request. |
| Status |
The implementation statuses of the entities (Implemented or Not implemented). |
Implementation status versus access request status
On an access request page, the Status column in the Implementation section shows the current access state of the individual entities. This is called the implementation status, and it can change over time. By contrast, the status of an access request is permanent, showing the outcome when the request was closed. You can find the status of an access request in the Status column on the Access requests page.