Skip to main content
Access requests let your colleagues request the apps, roles, and permissions they need — and let you control exactly who can see what, and what happens when they submit a request. This page explains how the system works and points you to the right place to get started.

New here? Start with a guide

If you’re setting up access requests for the first time, pick the guide that matches your situation:

Self-service requests

Make entitlements requestable in about 5 minutes. A good first look at how access requests work in C1.

SSO app requests

Set up requests for apps managed through Okta, OneLogin, or Microsoft Entra.

AWS JIT access

Configure just-in-time access to AWS resources via Identity Center.

GCP JIT access

Configure just-in-time access to Google Cloud Platform projects and roles.

On-call access control

Automatically grant or make available the right access when someone goes on-call.

How the system works

Configuring access requests involves two independent concerns: who can request an entitlement, and how that request is handled once submitted. C1 gives you separate tools for each.

Who can request (catalog visibility)

An entitlement only appears in the access catalog for users who are part of its audience. C1 gives you three tools to control this:

How requests are handled (request settings)

Request settings control what happens after a request is submitted: which approval policy routes it, how long the access lasts, and whether emergency access or a request form applies.

How settings are resolved

When someone requests an entitlement, C1 uses this order of precedence to determine the effective request settings:
  1. Locked entitlement — if Lock configuration is enabled on the entitlement, its own settings are used and no configuration rules apply.
  2. Entitlement configuration rules — the first rule whose condition matches the entitlement provides the request settings. Any fields the rule leaves empty fall back to the entitlement’s own settings.
  3. Entitlement settings — the settings in the entitlement’s Access controls (when not locked, these fill in any gaps left by a matching rule, or apply in full if no rule matches).
  4. App-level defaults — the request policy set on the app’s Access requests card.
  5. Built-in fallback — app owner approval.
When you set an app-level request policy on the Access requests card, C1 automatically creates a corresponding entitlement configuration rule called “Access request defaults.” You can view and edit it from the app’s Entitlement management card.

Which tool should I use?