IT & Engineering · Approvals & compliance
Access Request and Approval
Starts when: A user requests access or a role change
Free plan · Outcome verification included · You approve every connection
How it runs
Six stages, from the moment it starts to the checks that keep running afterwards.
It starts
A user requests access or a role change
Awish plans it and asks for each app
The apps it needs are connected one at a time, with your permission, before anything runs.
It does the work
Exactly as the request below describes, across the connected apps.
It stops where a person should decide
Privileged and admin access always requires the designated security approval, and may require MFA verification.
It verifies the outcome
After each run, Awish checks that the ticket, alert or access change was applied and recorded.
It keeps monitoring
Failures, silent failures and connection health are watched on every plan; anomalies, root cause and recommendations on Business.
The request it runs
This is what opens in chat when you use the template. Change any part of it before anything connects.
“Build an automation for the access request and approval workflow. Trigger it when a user requests access or a role change. It should validate the identity, employment and manager, check the role policy, collect the approvals, provision the approved group or app access, set an expiry when the access is temporary, and log the evidence. Connect it with Okta, Jira Service Management and Slack. Privileged and admin access always requires the designated security approval, and may require MFA verification.”
- Okta
- Jira Service Management
- Slack
Monitoring included
What Awish watches once this template is running.
- Outcome verificationEvery plan
- Silent-failure detectionEvery plan
- Connection healthEvery plan
- Hours saved and ROIEvery plan
- Anomaly detectionOn Business
- Root-cause explanationOn Business
- Recovery recommendationOn Business
Questions about this template
Can I change where it stops for approval?
Yes. Open the template in chat and say where you want it to stop. The plan updates before anything connects.
What if one of these apps is not connected yet?
Awish asks you to connect each app it needs, one at a time, before the workflow runs. You can decline any of them.
How does Awish know this workflow worked?
After each run it checks that the ticket, alert or access change was applied and recorded, in the app where that should happen. If a run reports success but the result is missing, it flags a silent failure.
Run it on your own apps
It opens in chat with the request written. See the plan, approve each connection, and Awish verifies the outcome from the first run.
Free plan · No credit card required