Access Requests FAQ
This is a placeholder page. Please see the links below for any child pages that exist.
Access Requests are owned by the Corporate Security Helpdesk team. All onboarding, offboarding and role change (career mobility) requests are owned by the People Connect Team.
If you have any access requests related questions, please reach out to #it_help
in Slack or the tool provisioner in Slack.
Role based entitlements are a pre-approved set of permissions that are granted to all people in a role. Make sure that whatever set of permissions you are adding to these templates should be granted to anyone with that role.
Role based entitlements need to be approved only once, when the template is created, and they don’t need to be approved again on a case-by-case basis.
These templates cannot be edited to remove or add extra permissions once created, unless those changes are approved by a manager (or higher) of the team the role belongs to. Note that an approval is still required even if a change comes from a manager or higher on a baseline entitlement template to mitigate the risk of a permission change being pushed through by a single team member.
We have decided to remove all SOX applications from the Role-Based Entitlements templates. Therefore, any access that is requested for our SOX-in-scope systems should follow the standard A/R process outlined here in our handbook. The impact to you is for any access going forward that was granted automatically via a role based entitlement will now need to be requested via a standard A/R so we can ensure approvals are properly captured.
Please note when editing an existing template or creating a new one do not include access of any kind to a rolebased access template. Full listing of SOX applications can be found here
@gitlab-com/business-technology/end-user-services
in the issue, with no particular SLA.#it_help
channel in Slack with a note on why it is urgent.dept::to do
. It is up to the department to manage the workflow on who works the issues to completion.If you need to initiate an Access Request process for a new item in the tech stack:
provisioner
deprovisioner
This is a placeholder page. Please see the links below for any child pages that exist.
d748cf8c
)