← All postsHow-to

Access request form: granting system access with approval and a record

An access request form makes sure every account and permission is approved by the right owner and can be reviewed later. What to capture, who approves, and how access gets removed.

How-toA

An access request form is the controlled way to ask for an account, a role or a permission on a system. It records who needs access, to what, at what level, why, and who approved it. That record is what auditors, security reviews and incident investigations ask for — and what lets access be removed cleanly when someone changes role or leaves. Access granted informally is the access nobody remembers to take away.

What an access request form should capture

  • The person who needs access, their role and their manager.
  • The system or data set, and the specific role or permission level — not just "access".
  • The business reason, tied to the person's role.
  • Start date and, for temporary access, an end date.
  • Approval from the system or data owner, not only the requester's manager.
  • Confirmation of when access was granted and by whom.

Least privilege by design

Offer roles, not free text. A form that asks "what access do you need?" collects requests for administrator rights; a form that lists defined roles for each system steers people to the level their job requires. Where a request asks for elevated access, require a stronger justification and a shorter end date.

The approver should be the owner of the system or data, not only the requester's manager. Managers know the person; owners know what the access exposes.

The access lifecycle

  1. Request submitted with system, role and reason.
  2. Manager confirms the business need; system owner approves the access level.
  3. IT grants access and records the date and the administrator.
  4. Temporary access expires automatically or is reviewed on its end date.
  5. Role changes trigger a new request for new access and removal of access no longer needed.
  6. Leavers have all access removed on their last day, using the recorded grants as the checklist.

Records that make access reviews possible

Ettex Forms can run the access request form with role lists per system and approval fields, and each approved request becomes a record in Ettex Records. When the periodic user access review comes around, owners review a list of recorded grants rather than trying to reconstruct who has access from each system separately. Ettex does not provision accounts in other systems automatically — it holds the request, the approval and the evidence of the grant.

Access request system vs form

  • A form plus a register suits organisations with a manageable number of systems and administrators.
  • An identity governance or access request system becomes worthwhile when access is provisioned automatically across many applications.
  • Either way, the same data is needed: who, what, level, reason, approver, dates.
  • Tie access requests to the information security policy so the rules are written once.
  • Include access responsibilities in security awareness training for approvers.

Frequently asked

Who should approve an access request?

The requester's manager confirms the need; the owner of the system or data approves the level. For privileged access, add security approval.

How often should access be reviewed?

Commonly quarterly for privileged or sensitive systems and annually for others. The review is only practical if access grants were recorded when they were made.

Is an access request form the same as a subject access request?

No. An access request form asks for system permissions. A subject access request is an individual asking an organisation for a copy of their personal data under data protection law.

DK
Written by Daria K.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.