The preservation of one auditable path from the original request to the final entitlement assignment. It matters because access governance breaks when the decision, approval, and provisioning steps are split into disconnected systems or informal side channels.
What Request-to-Grant Continuity Preserves
Request-to-grant continuity is the control story behind a clean access decision trail. It ensures the original request, approval, and final entitlement assignment remain connected so auditors and governance teams can explain why access exists.
That continuity matters because access decisions lose evidentiary value when workflow steps are split across email, ticket comments, spreadsheets, or local admin actions. The result is often a technically granted permission with no reliable chain of accountability.
Why the Continuity Chain Matters
Continuity is not just documentation discipline. It is what keeps the approval context attached to the entitlement outcome, so the organisation can distinguish a justified grant from an unreviewed or orphaned permission.
When the chain is intact, reviewers can trace who asked, who approved, what was approved, when it was provisioned, and whether the granted access matches the stated need. That traceability is essential for recertification, investigations, and control assurance.
Where continuity is weak, the entitlement may still be valid in a technical sense, but the governance record becomes unreliable. That creates a blind spot for access review, exception handling, and post-incident reconstruction.
Where Request-to-Grant Continuity Breaks Down
Breaks usually happen at the seams between systems rather than in a single control failure. A request may be approved in one platform, fulfilled manually in another, and never reconciled back to the original business justification.
Common failure points include off-platform approvals, service desk shortcuts, emergency access handled outside normal workflow, and provisioning steps that do not write back to the original record. Even when each step is individually defensible, the overall chain can still be incomplete.
Continuity also weakens when the access decision is described in vague terms, because the final entitlement cannot be checked against a precise request. A loosely defined request makes it hard to tell whether the grant was appropriate, excessive, or partially fulfilled.
What Good Continuity Looks Like
Good continuity creates a durable association between request, approver, entitlement, and effective date. The record should support later review without requiring people to reconstruct the decision from side conversations or tribal knowledge.
In practice, this means the governing system must preserve identifiers and timestamps across the workflow, not just the approval outcome. The trail should show both the decision and the provisioning action that implemented it.
For access governance, the best indicator is whether an independent reviewer can follow the same path from business request to actual privilege assignment without ambiguity. If that path is easy to lose, the control is weak even if approvals technically exist.
Risk and Threat Considerations
Broken request-to-grant continuity creates governance exposure because it weakens the proof that access was granted for a legitimate reason. It also makes it easier for excessive, stale, or exception-based permissions to persist without being challenged.
Failure mechanism: The approval, fulfilment, and entitlement record diverge, so the organisation can no longer reliably reconcile what was requested with what was actually granted.
Impact: Audit evidence degrades, recertification becomes less trustworthy, and investigators may be unable to prove whether access was authorised, over-scoped, or granted through an informal side channel.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Defines lifecycle control over account requests, approvals, and provisioning. |
| AU-2 — Event Logging | Logs preserve the evidence trail needed to connect request and grant actions. | |
| AU-12 — Audit Record Generation | Audit records provide the transaction trail for reconstructing entitlement decisions. | |
| Recommendation — Require traceable account-request records that link approvals to the resulting entitlement. Log request, approval, and provisioning events with correlated identifiers. Generate audit records that retain the request-to-grant chain end to end. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | Requires controlled granting, review, and removal of access rights with accountability. |
| A.5.15 — Access control | Sets the policy basis for ensuring access decisions remain authorised and reviewable. | |
| Recommendation — Tie access-right grants to documented approval and review evidence. Define access-control rules that preserve approval-to-entitlement traceability. | ||
Practitioner Guidance
What to watch for: Treat any approval that cannot be traced to a specific entitlement as a control defect, not a paperwork issue. The practical test is whether the organisation can recover the full decision path months later without depending on screenshots, inboxes, or manual recollection.
Governance implication: Ownership should sit with the access governance process, not only with the workflow tool. The control objective is continuity of evidence across the request, approval, and provisioning boundary, because that is where accountability is most often lost.