Access Request Management
bridge self service access request management provides a centralized experience for managing access to accounts and access groups users can view their account memberships, assigned access groups and current permissions, request access to new accounts or additional access groups within an account, track submitted requests and manage pending requests from a single interface by providing visibility into access levels, request history, and request status, the solution simplifies access management, enhances the self service experience, and eliminates the need for users to switch between application (ex arms) to request and manage access for approvers, a dedicated workspace streamlines access governance by enabling the review, approval, rejection and revocation of access requests, supporting a more efficient and scalable access management process navigate to access request management administrators can navigate to the access request management page to view, review and manage user access requests within their account this page provides a centralized location for tracking request status and taking appropriate actions as needed from the main menu , go to administration → access management → bridge access management → access request management a valid account is required to use access request management users can view account access, submit access requests and track request status the approval requests tab is available only to users with approver roles, such as administrator or kyndryl account manager accessing my accounts to view the account details, follow these steps on the access request management page, review your access information on the my accounts tab this tab provides a centralized view of all accounts and access groups associated with your user id, including account name account id country segment id account description identify the account name and expand an account to view the access groups associated with it view access group details, include access group name members description status select view details to view the account details, including customer accounts, service provider accounts and all access groups associated with a specific account the view membership only toggle on the account details page controls which access groups are displayed for the selected account use this toggle to switch between viewing only your current memberships and all access groups available within the account view membership only = on displays only the access groups that you currently belong to within the selected account this view helps you quickly review your existing access and permissions view membership only = off displays all access groups available within the selected account, including both the access groups you already belong to and those you do not currently belong to this view helps you identify additional access groups that may be available and request access to them through the edit access workflow requesting for access to an account all kyndryl users can submit access requests for accounts they are not currently a member of this self service capability allows you to search for the desired account, select one or more access groups, provide a business justification, and submit the request for approval once submitted, you can track the request status and review request details from the my requests page my requests page displays all submitted access requests and their current status the request table includes the following information for each request request date the date the access request was submitted account name the name of the account for which access was requested access groups the access groups included in the request account id the unique identifier of the requested account status the current state of the request, such as pending, approved, rejected, cancelled or expired my requests page allows you to perform the following actions view details opens the details page for a selected access request, where you can review request information, including account details, access groups, request justification, access group descriptions, approval or rejection comments (if available), approval or rejection dates, approver information and the current request status cancel request available only when the request is in pending status use this action to withdraw a request before it is reviewed by the account administrator there are two key flows where you can request access if not currently a member of an account (scope 1) request access to a new bridge account (for users who are not members of the account) (scope 2) request access to different access groups (for users who need access to additional access groups in an account they already belong to) requesting for access to a new bridge account or different access group within an account this request allows users who are not currently members of a account to request access to that account follow these steps to initiate an access request to a or aiops account that you are not currently a member of from the access request management page, click request access locate the account that you want to access you can search for an account by name or use the country and segment id filters to narrow the list of available accounts and click next select the access groups that you want to join for the selected account you can request access to one or more access groups as part of the same access request access groups are organized into two categories bridge access groups for platform level access service access groups for service specific access to access the functionality, users must belong to at least one bridge access group to ensure this requirement is met, the bridge viewer access group is selected by default when submitting an access request; this can be unselected as needed the bridge viewer access group provides the minimum level of access required to use the functionality enter a business justification (500 character minimum) for the access request and click next review the request summary and click submit whenever an access request is submitted, the request is routed to the appropriate approver for review, and an email notification is sent to notify the approver of the new access request the edit access workflow creates a new access request for the selected account and does not modify previously submitted requests if a submitted request is not reviewed by an account administrator within 30 days of submission, its status is automatically updated to expired approval access request management available only to users with the approver role, such as dpes (delegated platform engineers) and account administrators, the access request management page includes an approval requests tab for reviewing, approving, rejecting and revoking access requests this approval request tab displays a list with some key metadata, such as account id account name access group requestor email requestor justification country expiration date the access request gets expired 30 days from the date of request approved by email id of the approver status system to display approve or reject status alongside every user access request allowed actions approve request reject request view details view details should include all the above metadata including approver's role, approved date & time approval or rejection comments (if available) approvers can manage requests only within the account they are currently viewing the following actions are available to approvers viewing the approval request details to review all information related to a submitted access request, follow these steps from the main menu , go to bridge access management → access request management → approval requests approval page on the approval requests page, locate the request, click the ellipsis ( ) menu and select view details the following information is displayed requested access groups requestor email requestor justification approver role approval or rejection comments (if available) approval or rejection date and time current request status unreviewed and reviewed access requests the approval requests page enables approvers to review, approve and reject user access requests for the accounts they manage the page is divided into the following sections unreviewed the unreviewed section displays access requests that are awaiting a decision approvers can review request details, including the requested access groups and business justification, and then approve or reject the request as appropriate reviewed the reviewed section displays access requests that have already been processed this section provides a historical view of approved and rejected requests, allowing approvers to review request details, approval decisions, dates, and associated comments each section displays a table with key information for each request, including the account name, requested access groups, requester email address and the business justification provided by the requester approvers can use this information to evaluate requests and monitor their status throughout the approval process approve or reject user access requests to review and either approve or reject an access request, complete the following steps from the main menu , go to bridge access management → approval requests click the ellipsis menu for the request and choose approve or reject as appropriate the request details page will display detailed information about the access request, including the metadata for all requested access groups and the requester's business justification details page also provides the capability to approve or reject as appropriate a confirmation window is displayed, click confirm approval or confirm rejection if rejecting a request, you must provide a rejection justification before confirming the rejection after the request is submitted, its status is updated to approved or rejected , the approval date is recorded, and a confirmation notification is displayed request details page after approving or rejecting a request, the reviewer is automatically taken to the request details page to verify request information before deciding and to confirm the outcome after the request has been processed from this page, following information can be reviewed request status (approved, rejected, or pending) account details, including the account name and account id requester information, such as the requester's name and email address account expiration date and country requested access groups, including the group name, description, and current member count requester's business justification explaining the need for access this information helps approvers determine whether the requested access is appropriate and supports informed approval decisions