Requestable catalog
Bundle entitlements from an application into something a non-technical user can understand and ask for.
A self-service catalog with configurable approval policies and an approval queue — so access is requested, approved and recorded in one flow.
When getting access means emailing someone who knows someone, the decision is undocumented and the outcome is inconsistent. Access requests give users a catalog of what they can ask for, route each request through the approval policy that applies to it, and provision the result automatically once approved — with the whole chain recorded.
The mechanics behind the capability — what the platform does, and where it does it.
Bundle entitlements from an application into something a non-technical user can understand and ask for.
Route by application owner, line manager or a defined approver, with single or multi-step chains as the risk warrants.
Toxic combinations are evaluated before the grant, so conflicting access is prevented rather than discovered later.
Approvers see what is waiting on them in one place, which is what keeps requests moving.
Who feels the difference once Access Requests is in place, and how.
End users
A governed path is faster than an informal one, which is what stops people routing around it.
Audit
Every grant has a requester, an approver and a justification attached, which is exactly what an auditor asks for.
Application owners
Approval sits with the people who understand the consequences, rather than with a central team guessing.
Governance
Checking separation of duties before approval avoids the far harder job of unwinding it afterwards.
It works because the other capabilities share the same identity fabric. The quickest way to judge that is to watch it run against your own use cases.