Join our Newsletter — 33% off our NHI Course

Access requests and IAM governance: what teams miss in ticketing

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Access requests still dominate IT support because fragmented approval paths, changing role needs, and manual handling create delay and risk across software access, according to Zluri's overview of IT support requests. The real issue is governance: access workflows reveal where identity controls, review processes, and accountability break down.

Editorial analysis by NHI Mgmt Group, based on content published by Zluri: “IT Support Requests - An Overview”.

Key questions

Q: What breaks when browser access requests are handled manually instead of through a ticketing workflow?

A: Manual handling usually slows approvals, creates inconsistent decision-making, and makes it easy for temporary access to linger long after the original need has passed.

Q: Why do access requests become a governance risk as organisations scale?

A: Access requests become risky when approval paths multiply faster than policy control.

Q: How should teams combine automation and human approval in access governance?

A: Use automation for bounded, repeatable decisions such as pausing obvious drift, triggering cleanup or routing low-risk changes.

Practitioner guidance

  • Map recurring access requests to role design gaps Review repeated requests by application, department, and job function to identify entitlements that should be role-based rather than manually approved.
  • Separate approval authority from ticket routing Define who can approve access, which entitlement classes they own, and what evidence is required before the ticket can move to fulfilment.
  • Trigger access changes from lifecycle events Tie mover and leaver events to access adjustment workflows so permissions are updated when job scope changes, not after users raise a support case.

Bottom line: Access requests are often the most visible sign that entitlement design and ownership are not keeping pace with the business.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Access requests are the visible symptom of poor entitlement governance: When employees repeatedly need approvals for routine software access, the underlying problem is usually role design and ownership, not the ticketing workflow itself. Ticketing can move requests around, but it cannot fix misaligned access models or inconsistent decision rights. The governance question is whether access is being granted from policy and lifecycle logic, not from whatever queue receives the request. Practitioners should read request volume as a control signal, not an operational nuisance.

A question worth separating out:

Q: How do IAM teams know whether access governance is working?

A: IAM teams should look for fast revocation after role change or departure, accurate entitlement data, and low numbers of orphaned or over-provisioned accounts. If access creation is easy but removal is slow, governance is incomplete. The strongest signal is whether access still matches business need after the identity changes.

👉 Read our full editorial: Access requests are an IAM governance problem, not a ticketing one


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.