TrustPortDocs

Start with entitlements

In the dashboardGovernance›Entitlements›Create entitlement

An entitlement is something a person can ask for, like “Production database admin” or “Finance reports”. For each one, set:

FieldWhat to put
NameWhat people will recognise in a request
SystemWhere the access lives, e.g. TrustPort, AWS, your product
Risk levelLow, medium, high or critical, so approvers know how carefully to look
Grants roleThe role TrustPort grants on approval. Leave empty for manual fulfilment
Map entitlements to roles wherever you can. Approval then grants the role straight away, and revoking it in a review really removes it.

Access requests

1RequestWho, what, grant or revoke, and why
2Approve or denyBy a different admin, with a note
3FulfilRole granted or removed automatically
  1. Raise a request
    In the dashboardGovernance›Access requests›New request

    Choose the user, the entitlement, whether to grant or revoke it, and give a reason.

  2. Someone else decides

    Pending requests wait in the Access requests tab. An admin approves or denies with an optional note. Nobody can approve their own request.

  3. Access changes

    If the entitlement grants a role, TrustPort grants or removes it on approval. Otherwise, fulfil it by hand in the target system.

Access reviews

A review asks someone to confirm, person by person, that access is still needed. Run one each quarter for privileged access, or whenever an auditor asks.

  1. Start the review
    In the dashboardGovernance›Access reviews›Start review

    Name it (“Q4 privileged access”), choose the reviewer, a due date in days, and the entitlements in scope. Only entitlements that grant a role can be reviewed. TrustPort takes a snapshot of everyone who holds them right now.

  2. The reviewer decides each item

    For each person, they choose Keep or Revoke and can leave a comment. Only the assigned reviewer or an admin can decide.

  3. Close it

    Revoked items lose the role immediately. Close the review when every item is decided; progress is shown as you go.

Every request, decision and change is recorded, so you can show an auditor who had access, who approved it and when it was last checked.

© TrustPort IdentitySomething unclear? Tell us and we'll fix the page.