New here? Start with a guide
If you’re setting up access requests for the first time, pick the guide that matches your situation:Self-service requests
Make entitlements requestable in about 5 minutes. A good first look at how access requests work in C1.
SSO app requests
Set up requests for apps managed through Okta, OneLogin, or Microsoft Entra.
AWS JIT access
Configure just-in-time access to AWS resources via Identity Center.
GCP JIT access
Configure just-in-time access to Google Cloud Platform projects and roles.
On-call access control
Automatically grant or make available the right access when someone goes on-call.
How the system works
Configuring access requests involves two independent concerns: who can request an entitlement, and how that request is handled once submitted. C1 gives you separate tools for each.Who can request (catalog visibility)
An entitlement only appears in the access catalog for users who are part of its audience. C1 gives you three tools to control this:How requests are handled (request settings)
Request settings control what happens after a request is submitted: which approval policy routes it, how long the access lasts, and whether emergency access or a request form applies.How settings are resolved
When someone requests an entitlement, C1 uses this order of precedence to determine the effective request settings:- Locked entitlement — if Lock configuration is enabled on the entitlement, its own settings are used and no configuration rules apply.
- Entitlement configuration rules — the first rule whose condition matches the entitlement provides the request settings. Any fields the rule leaves empty fall back to the entitlement’s own settings.
- Entitlement settings — the settings in the entitlement’s Access controls (when not locked, these fill in any gaps left by a matching rule, or apply in full if no rule matches).
- App-level defaults — the request policy set on the app’s Access requests card.
- Built-in fallback — app owner approval.