1. Request
Users can request accesses on-demand using the shortcut/request or a button on the home tab of the AccessOwl Slack app. Requests can also be made on the web, directly from the App Hub.
Here’s how it works:
- Only if you don’t have a manager set: You’re asked to provide the name of your manager.
- By default access requests need to be approved by your direct manager.
- After approval, provisioning requests with all the necessary details are sent to the responsible application admins or to AccessOwl for automated provisioning.
If the app you need isn’t listed in the request form, you’ll see an Enter new application option. This adds a custom application (an internal or in-house app of yours) so it can be requested. It is not a way to request a SaaS app that AccessOwl does not support yet. For more on adding apps, see Adding an Application. If you need an integration for an app that isn’t available yet, contact AccessOwl.
Special Request Type: No Permission Selection Required
For certain applications, you may not want users to choose their own permission level. Instead, let them describe the access they need in a freeform text field. The application admin can then review the request and assign the correct permission level.Setup
To set up an application to not require a permission selection, open the app’s permissions and unselect the following checkbox:
Example
Time-based Requests
Some applications let you pick how long you need the access for. If the app is set up for it, the request form shows a Duration step, and the access is automatically removed again when the duration runs out. See How Time-based Access Works.Mandatory Resources
Some applications have mandatory resources that must be requested before other permissions can be granted. If you try to request access without including the required mandatory resources, you’ll see a validation error listing the permissions you need to include.If you already have access to the mandatory resource, you can request additional permissions without including it again. If the mandatory resource is configured with Any child resource required, holding or requesting any one of its child resources is enough.
2. Approval
AccessOwl offers different options for approval policies, which are managed by your AccessOwl Org Admins. The default option is manager approval, and a policy can chain several approval steps. Each approver has the option to either approve or deny, and you receive a notification after every decision. To see where your request is sitting, open it under My Requests in the App Hub. It lists every step of the approval chain, who the approvers on each step are, and which step is currently pending. The chain is fixed when the request is created, so a later change to the policy does not alter it. See Why does an approver in my chain not match the current policy or Business Owner?3. Provisioning
The final step is the creation of the requested access. Depending on whether the application is managed by an internal application administrator or via an integration of AccessOwl, there are two options:- App without integration
- App with integration
After the access has been approved, the application administrator receives a notification in Slack. They have the option to grant or reject the access. You will be informed when the application administrator has finished the task. If rejected, you will also be provided with a rejection reason.The application administrator’s complete list of open provisioning tasks lives in Slack. Mark as granted in the web app is for overriding or closing out a single request, not for viewing everything assigned to them.
Added an integration after requests already came in? Open the pending request and click Retry Automation to run the now-available automation. You don’t need to resubmit the request.

A request was rejected at the provisioning step. Why is it not under Removed access?
A request was rejected at the provisioning step. Why is it not under Removed access?
Removed access lists access that was granted and later revoked. When a request is rejected at the provisioning step, the access was never granted, so there is nothing to remove and nothing appears on the user’s profile.The record stays under Access Requests with the rejection reason, which is the audit trail. The rejection reason on that record tells the requester who to talk to before resubmitting. To try again, submit a new request for the same application and user, the rejected one cannot be reopened.
How do I report on access requests?
How do I report on access requests?
Open Access Requests in the admin interface. The list holds every request your organization has raised, so the number of rows in a period is your request volume.Requests created by a scheduled onboarding carry the request reason Onboarding a new user. Every other reason is a request an employee raised themselves, so filter by reason to separate the two.To measure how long requests take, export the list to CSV. Each row records when the request was approved and when the access was granted (provisioned), so you can calculate approval time and provisioning time per request. The list itself does not show these durations.There is no separate analytics dashboard for requests. The list and its export are the reporting surface. For a live feed instead of a periodic export, request webhooks fire when a request is created, approved, and granted.
Pending Dependency Status
When you request multiple permissions and some depend on mandatory resources, your requests may show a Pending dependency status. This means the request has been approved but is waiting for the mandatory resource to be provisioned first. Once the mandatory resource is granted, dependent requests will automatically proceed to provisioning.Revoke Your Own Access
If you no longer need an access you were granted (for example, time-based access you requested for a one-off task, or an app you used in a previous role), you can revoke it yourself directly from Slack.1
Open the AccessOwl Slack app
Go to the AccessOwl home tab in Slack.
2
Click Revoke Access
Use the Revoke Access button on the home tab.
3
Select yourself
Choose your own user, then pick the app and permission you want to give up.
Revocations have no approval flow. This is not specific to self-revocations. A manager can revoke access for any of their direct reports. See the Revoke app access and Manage access of direct reports rows in Roles and Permissions.Once a revocation is confirmed, AccessOwl deprovisions the access automatically if the app has an integration, or notifies the application admin to remove it.

