Access Request
An access request is the process by which a user asks for permission to use a specific resource, system, application, or set of information within an organization. It is typically the starting point for granting someone the access they need to do their job, and in most deployments the request is reviewed and approved before any access is actually provisioned.
An access request is a user-initiated activity within identity governance and administration (IGA) in which a principal seeks authorization to access specific resources, systems, applications, or data in an IT infrastructure. It is an administrative, lifecycle-oriented workflow, commonly routed for approval by designated stakeholders (which may include business, HR, or legal reviewers depending on the resource and organizational policy) before entitlements are provisioned, and is distinct from runtime access enforcement such as token validation or PDP/PEP evaluation. Note that the terminology overlaps with, but should not be conflated with, a data subject access request (DSAR) under privacy regimes, which is a request by an individual to obtain their own personal data rather than an entitlement to operate a system.
Why it matters
The access request is typically the entry point of the joiner-mover-leaver lifecycle within identity governance and administration (IGA). Because it is the moment where a principal formally seeks authorization to a resource, system, application, or data, it is where organizations have the opportunity to enforce policy before any entitlement is provisioned. A well-structured access request workflow creates the audit trail that later feeds access certifications, segregation-of-duties checks, and compliance reporting; a weak or informal one produces standing access that no one can later justify.
The review-before-provisioning pattern is what distinguishes a governed access request from ad hoc grants. In most deployments, requests are routed to designated stakeholders for approval, and depending on the resource and organizational policy those reviewers may include business owners, HR, or legal. For example, some institutions require that non-emergency requests to access another user's data be approved by both HR and Legal before access is granted, reflecting how sensitive resources can carry heavier approval requirements than routine application access.
A recurring point of confusion is terminological rather than technical: an access request in the IGA sense is not the same as a data subject access request (DSAR) under privacy regimes. A DSAR is an individual asking an organization for their own personal data (or, in some services, the data of a child or relative), whereas an IGA access request seeks an entitlement to operate a system. Conflating the two can misdirect workflows, ownership, and compliance obligations, so teams should keep the distinction explicit.
Who it's relevant to
Inside Access Request
Common questions
Answers to the questions practitioners most commonly ask about Access Request.
