Skip to main content
Time-based access lets you time-box a grant: the user picks a duration when requesting, and AccessOwl automatically takes the access away again when the duration runs out. It is configured per application by Org Admins. For what happens once it’s switched on, see How Time-based Access Works.

Enable it for an application

1

Open the application's settings

Go to the application in AccessOwl and edit its general settings.
2

Turn on Time-based Access

Enable the Time-based Access toggle. A duration picker appears below it.
3

Choose the available durations

Add every duration users should be able to pick from. Users can only choose from what you add here.
Turning the toggle back off returns the application to permanent access only. Grants that are already running keep their expiry — switching off stops new time-boxed requests, it doesn’t cancel existing ones.

Choosing durations

You can offer any combination of these options: Keep the list short. A picker with three sensible options gets used; one that offers everything above makes people guess.
Unlimited is not a duration — it’s the option that lets users request permanent access. Keep it in the list if permanent access should still be possible for this app. Remove it if every grant must expire.

Limitation: freeform requests

Time-based access requires users to select permissions. It cannot be combined with freeform requests, where the user describes the access in a text field instead of picking permissions.If you try to configure both, you’ll get a validation error. Either remove the time-based durations, or re-enable Require users to select permissions on the app’s resources.
The reason is that AccessOwl needs to know exactly which permissions were granted in order to take precisely those away again at expiry. A freeform request doesn’t carry that information.
Last modified on September 14, 2026