Access requests

In Data Access, an access request is automatically generated to ensure proper authorization when users interact with the entities that they do not own, or when they request access on data objects. Access requests ensure that data owners stay in control of who can access their entities, giving them full visibility and control over data sharing decisions.

When access requests are generated

Access requests are automated by-products of your governance actions. They are generated in the following scenarios.

Scenario Description
Adding unowned data objects When you add a data object that you do not own to your access control, an access request is generated. The owner of the data object must approve the request before their data is added to your access control.
Adding unowned access controls When you add an access control that you do not own to the What component of your access control, an access request is generated. The owner of the access control must approve the request before their access control is added to your access control.
Requesting access from an asset

If you are granted on-request access in an access control, a preapproved access request is generated when you request access from an asset that is linked to the access control. An on-request access means that you are automatically granted access for a predefined duration (for example, 14 days), after which the access is revoked.

Viewing access requests

To view access requests, on the Data Access landing page, in the left pane, click Access requests. The Access requests page contains the access requests that you made and the access requests that are assigned to you. The page also contains the access requests in which you are mentioned in a comment.

You can view all access requests only if you have a global role with the Data Access > View All Access And Usage or Data Access > Manage All Access global permission, for example, the Data Access Observer or Data Access Manager global role.

Tip To view only the access requests that you made, on the main toolbar, click your avatar > Access requests.

How access requests are grouped

When you add multiple unowned data objects to your access control, one combined access request is generated, even if those data objects have different owners. However, when you add multiple unowned access controls to your access control, a separate access request is generated for each access control, unless they share the same owners.

The "Access requests" page

The Access requests page contains the following information.

Column Description
Access request The ID of the access request, shown as a clickable link that opens the access request page.
Requested access

The data objects or the access controls (entities) for which the access is requested.

Assignees

The users who are responsible for implementing or closing the request. These are the owners of the requested entities.

Requester The user who initiated the access request.
Created on The date and time when the access request was generated.
Status

The status of the access request. You can use the Status filter to narrow the list to one or more specific statuses.

Statuses of access requests

An access request can have one of the following statuses.

Status Description
Awaiting approval

The request is awaiting approval in a custom workflow. This status appears only if a custom workflow is configured for access requests. Otherwise, this step is skipped and the request moves directly to the Awaiting implementation status.

Awaiting implementation

The request is waiting for the responsible owner to implement access in the target data source.

Implemented

Access to all requested entities is implemented in the target data source.

Partially implemented

Access to some, but not all, requested entities is implemented in the target data source.

Rejected

No access was implemented in the target data source before the request was closed.

Canceled

The requester (or an authorized user) canceled the request before access was implemented.

The access request page

The access request page opens when you click an access request ID on the Access requests page. It contains details to help you decide whether to implement or close the request.

Image of an access request page

The "What access is granted"section

The What access is granted section on the access request page contains the following information.

Field Description
Access requested on

The data objects or the access controls (entities) for which access is requested. These are the entities that a user who does not own them added to an access control.

Access requested for

The access control from which the access request originated. This is the access control to which the user added the entities, generating the access request.

Access requested until

The date and time when the access, if granted, expires. For data objects, the default value is Unlimited. For access controls, the date and time is set by the user who added them to the access control.

Purpose System-generated information about the origin of the access request.

The Implementation section

The Implementation section on the access request page contains the following information.

Column Description
Data object (or Access control)

The data objects or access controls for which access is requested.

Permissions The permissions that are associated with the data objects.
All owners The identities that own the requested entities. These are the users who are tasked with reviewing the request.
Status

The implementation statuses of the entities (Implemented or Not implemented).

Tip You can use the Comments section on an access request page to post comments and view system logs such as who opened or closed the access request.

Implementation status versus access request status

On an access request page, the Status column in the Implementation section shows the current access state of the individual entities. This is called the implementation status, and it can change over time. By contrast, the status of an access request is permanent, showing the outcome when the request was closed. You can find the status of an access request in the Status column on the Access requests page.

Example Suppose that Yuki requests to add your data object, EMPLOYEE, to her access control. Once you approve the access request, the implementation status of the EMPLOYEE data object changes to Implemented, and the access request status also changes to Implemented. If, however, Yuki removes the EMPLOYEE data object from her access control later, its implementation status reverts to Not Implemented. However, the access request status still remains Implemented, as a permanent record of your past approval.

Related topics