Skip to main content
Loading...
Office & admin

Access Requests

Track access requests from justification through approval, review, and revocation with a working register, saved views, and a Monday recertification digest.

Included with every MangoApps plan.

Rolled out to every employee at AutoZone (125,000), PetSmart (50,000+), A.S. Watson and Raley's (20,000) — and at larger retailers we are not permitted to name.

Built for: Software And Technology · Financial Services · Healthcare Administration · Professional Services · Manufacturing

Overview

Access Requests is a working MangoApps register for recording who has access to which system, at what level, why it was requested, and when the grant must be reviewed. Every member can add records, and each record has typed fields for System, For, Level, Justification, Status, Granted, Review by, and Notes. Level starts with Read only, Standard, and Admin; Status starts with Requested, Granted, Declined, and Revoked.

Use the app when access decisions are otherwise scattered across email, chat, tickets, or a spreadsheet. The Awaiting decision saved view isolates Requested records for review. Active grants shows the current Granted population, while Recertify in 30 days identifies granted access with a Review by date approaching. The Overview screen provides a metric row and cards for a quick review, and the Register screen provides the full grid and action bar for updating records.

This template also creates two follow-up points: adding a record notifies the app owner, and every Monday at 08:00 the app owner receives an Access due for review digest based on the Recertify in 30 days view. It is suitable for access governance tracking, not for directly changing permissions in another system. It also should not replace a formal identity-management platform, emergency-access process, or evidence that a technical revocation was completed. Keep the register accurate by changing Status when decisions or lifecycle events occur.

Standards & compliance context

  • The register supports common access-governance and audit record-keeping expectations by linking a system, person, access level, justification, decision status, grant date, and review date.
  • The Review by field and Monday recertification digest support periodic access recertification, but your security policy should determine the required cadence and approver.
  • For regulated environments, align record retention, approval authority, privileged-access review, and revocation evidence with the standards and laws applicable to your organization.
  • A Granted or Revoked status documents the decision state in this app and should not be treated as independent proof that permissions were technically provisioned or removed.

General regulatory context for orientation only — verify current requirements with counsel or the relevant agency before relying on this template for compliance.

How to use this template

  1. Add the Access Requests app to your MangoApps workspace and confirm the app owner who will receive new-request notifications and the Monday recertification digest.
  2. Decide whether requesters, managers, administrators, or all members should enter records, noting that the starting posture allows every member to add, edit, and delete records.
  3. Log each request with the System, person in For, requested Level, Justification, and Status set to Requested, then add Notes when the request needs context.
  4. Review the Awaiting decision view and update the record to Granted, Declined, or Revoked while completing Granted and Review by dates whenever access is approved.
  5. Use the Overview screen for metrics and cards, and the Register screen to inspect the full grid and action bar alongside the Active grants and Recertify in 30 days views.
  6. Act on the Monday Access due for review digest by recertifying each listed grant, changing Status or Review by as appropriate, and recording the decision in Notes.

Best practices

  • Require a specific Justification that explains the business need rather than accepting entries such as "needed for work."
  • Record the exact System name and keep naming consistent so Active grants and recertification reviews are easy to filter and interpret.
  • Use Admin only when the request genuinely requires elevated control, and prefer Read only or Standard when they meet the stated need.
  • Set Review by when a request becomes Granted so it cannot enter the active population without a planned recertification date.
  • Treat Requested as undecided and never use it to represent access that has already been provisioned.
  • Use Notes to capture the decision context, exceptions, or confirmation that a technical revocation was completed.
  • Review the Recertify in 30 days view before Monday rather than waiting for the digest when a high-risk grant is approaching its deadline.
  • Limit deletion because an access decision may be needed later; where possible, use Declined or Revoked to preserve the lifecycle record.

What this template typically catches

Issues teams running this template most often surface in practice:

A Requested record has no decision owner or remains open after the access decision was made.
An Admin grant has no Justification explaining why elevated access is necessary.
A Granted record is missing its Granted date or Review by date, so its recertification window cannot be managed.
A former employee or transferred worker remains listed as Granted because Status was never changed to Revoked.
The System field uses inconsistent names, splitting one application's grants across multiple informal labels.
A Declined request is deleted instead of retained with its decision context in Notes.
A technical permission was removed, but the corresponding register record still says Granted.
The app owner receives a recertification digest but reviewers do not record the outcome or move the next Review by date.

Common use cases

IT administrator handling application requests
An IT administrator uses Awaiting decision to review incoming requests, checks the System, For, Level, and Justification fields, then records the outcome and dates. Active grants provides the current access population for routine administration.
Security team recertifying privileged access
A security team filters Active grants for Admin access and uses Review by to prioritize elevated permissions. The Monday Access due for review digest highlights grants entering the next 30-day review window.
Department manager approving team access
A manager reviews Requested records for systems owned by the department and records whether Read only, Standard, or Admin access is justified. Notes capture exceptions or conditions that should be revisited at recertification.
HR and IT coordinating role changes
When someone changes role, the responsible team locates their For record, verifies the current System and Level, and changes Status to Revoked where access is no longer needed. The register retains the decision trail instead of relying on a deleted spreadsheet row.
Audit coordinator preparing access evidence
An audit coordinator uses the Register screen and saved views to assemble a current picture of requests, active grants, decisions, and upcoming reviews. The fields provide a consistent starting record for follow-up with system owners.

Frequently asked questions

What access decisions does this template track?

It records the System, person the access is For, requested Level, Justification, Status, Granted date, Review by date, and Notes. Status options are Requested, Granted, Declined, and Revoked. This supports the full path from request to active grant and eventual removal.

Who should add and maintain access request records?

Every member can add records, which allows requesters or administrators to enter access needs as they arise. Assign an app owner or access administrator to review requests, update Status, fill in Granted and Review by dates, and record decisions in Notes. If broad entry is unsuitable for your process, confirm the access permissions during rollout.

How often are access grants reviewed?

Use the Review by field to set the next recertification date for each Granted record. The Recertify in 30 days view shows active grants approaching review, and every Monday at 08:00 the app sends the app owner an Access due for review digest. Set review dates according to your internal access policy and risk level.

Does this template satisfy access-control or audit requirements by itself?

It provides an operational record of requested access, approval status, level, justification, grant date, review date, and revocation. Those fields support common access-governance and audit evidence expectations, but the template does not determine your legal or regulatory obligations. Align retention, approval authority, review cadence, and access to the register with your organization's security policy.

What is the difference between this and an access spreadsheet?

The app keeps typed fields together with an Awaiting decision view, Active grants view, and Recertify in 30 days view. Its New access request automation notifies the app owner, while the Monday recertification list sends a scheduled digest. Unlike an informal spreadsheet, the working app gives reviewers defined screens and repeatable follow-up points.

Can we customize access levels, statuses, or review fields?

Yes, the template can be adapted in your MangoApps workspace to match your process. The starting Level options are Read only, Standard, and Admin, and the starting Status options are Requested, Granted, Declined, and Revoked. Confirm any added options and field changes with the people responsible for access governance before rollout.

Can this template connect to our identity provider or ticketing system?

The supplied template includes its register, saved views, screens, and two automations, but no identity-provider or ticketing integration is specified. Use it as the access decision register and verify available MangoApps integration options in a demo before promising synchronization. Do not treat a Granted record as proof that a technical system change happened unless that change is separately verified.

How should we roll out the Access Requests app?

Add the template to your MangoApps workspace, name the app owner, and agree who reviews Requested records. Import or enter current access grants with their Level, Granted date, Review by date, and Status, then test the Monday digest with a sample record. Start with one system or department and expand after confirming that reviewers close the loop by changing records to Granted, Declined, or Revoked.

What common mistake should reviewers avoid?

Do not mark access Granted without recording who the access is For, the requested Level, the Justification, the Granted date, and a Review by date. A request left in Requested can be mistaken for an active grant, while a revoked technical account can remain incorrectly listed as Granted. Reviewers should update Status promptly and use Notes for decision context.

Ready to use this template?

Access Requests runs on a platform app included with every MangoApps plan — pick a suite and it comes along.

Rolled out to every employee at AutoZone (125,000), PetSmart (50,000+), A.S. Watson and Raley's (20,000) — and at larger retailers we are not permitted to name.