IT CanvassTalk to an advisor
Architecture · LessonBy , SailPoint Trainer, 7 yrs · Published · IdentityIQ 8.4 · all levels

Request flow

How a self-service access request travels from submission to fulfillment.

Quick answer

A user requests access, the request is routed for approval, policy is checked, and on approval provisioning fulfills it.

Key takeaways
  • Purpose: let users request access and have it governed and fulfilled
  • Trigger: A user submitting an access request
  • Outcome: Requested access is approved and provisioned, or denied
  • Where it fits in the SailPoint architecture

The access request flow is the self-service journey by which a user asks for access and has it governed and fulfilled. It is the most visible part of IdentityIQ for ordinary end users and the mechanism that turns access from an opaque back-office process into a transparent, auditable one.

What triggers the flow

A user (or someone requesting on their behalf) opens the access request catalogue and selects roles, entitlements or applications to request. Requesting for others, a manager onboarding a team, is a common variant.

Step by step

  • 1. Submit. The requester chooses items from the catalogue and submits, optionally with a business justification.
  • 2. Routing. The request is routed to the appropriate approvers, defined by ownership, role owner, resource owner, manager, or a workflow.
  • 3. Policy check. Separation-of-duties and other policies are evaluated; a conflict may block the request or require an explicit exception approval.
  • 4. Approval. Approvers approve, reject or reassign. Multi-level approval chains are common for sensitive access.
  • 5. Fulfilment. On approval, the provisioning flow executes the change on the target system (automatically or via a manual work item).
  • 6. Notification and audit. The requester is told the outcome, and the full request-to-fulfilment history is logged.

What makes a good request experience

The catalogue is where governance meets usability. A well-designed catalogue presents business-meaningful items, roles and clearly-described entitlements, rather than cryptic technical group names, so users request what they actually need and approvers understand what they are approving. Poor descriptions here undermine every downstream control.

Requests and least privilege

Access requests are the controlled alternative to invisible, direct grants in target systems. Because every requested grant is justified, approved and logged, the request flow both satisfies auditors and supports least privilege, access arrives through a governed door rather than accumulating in the shadows.

Common pitfalls

  • A catalogue full of technical jargon that users and approvers cannot interpret.
  • Approval fatigue, so many requests that approvers rubber-stamp; scope approvals to what genuinely needs review.
  • No SoD check at request time, letting toxic combinations in that must be caught later.

Practice challenge

+0 XPStreak ×0
Question 1 of 3
What triggers the request flow?

Frequently asked questions

What does the term Request flow refer to in SailPoint?
The access request flow is the self-service journey by which a user asks for access and has it governed and fulfilled. It is the most visible part of IdentityIQ for ordinary end users and the mechanism that turns access from an opaque back-office process into a transparent, auditable one.
What is the practical takeaway on Request flow?
A user (or someone requesting on their behalf) opens the access request catalogue and selects roles, entitlements or applications to request.
What is worth remembering about Request flow in practice?
Requesting for others, a manager onboarding a team, is a common variant.
What tends to go wrong with Request flow?
A catalogue full of technical jargon that users and approvers cannot interpret. No SoD check at request time, letting toxic combinations in that must be caught later.
Want this with a live instructor and a lab tenant?
SailPoint IdentityIQ training →
Already working on SailPoint and stuck on a live ticket?Get an expert SailPoint developer on screen-share to finish your daily tasks with you. Deliver on time, protect your reputation and your job. Monthly support only, no task-wise plans.Task assigned · no idea where to startStill stuck · your job on the lineExpert joins your screenDelivered on timeExplore On Job Support