Access requests and reviews
Grant sensitive access through an approval, and check regularly that people still need what they have. Auditors ask for both; TrustPort keeps the record for you.
Start with entitlements
An entitlement is something a person can ask for, like “Production database admin” or “Finance reports”. For each one, set:
| Field | What to put |
|---|---|
| Name | What people will recognise in a request |
| System | Where the access lives, e.g. TrustPort, AWS, your product |
| Risk level | Low, medium, high or critical, so approvers know how carefully to look |
| Grants role | The role TrustPort grants on approval. Leave empty for manual fulfilment |
Access requests
- Raise a requestIn the dashboardGovernance›Access requests›New request
Choose the user, the entitlement, whether to grant or revoke it, and give a reason.
- Someone else decides
Pending requests wait in the Access requests tab. An admin approves or denies with an optional note. Nobody can approve their own request.
- Access changes
If the entitlement grants a role, TrustPort grants or removes it on approval. Otherwise, fulfil it by hand in the target system.
Access reviews
A review asks someone to confirm, person by person, that access is still needed. Run one each quarter for privileged access, or whenever an auditor asks.
- Start the reviewIn the dashboardGovernance›Access reviews›Start review
Name it (“Q4 privileged access”), choose the reviewer, a due date in days, and the entitlements in scope. Only entitlements that grant a role can be reviewed. TrustPort takes a snapshot of everyone who holds them right now.
- The reviewer decides each item
For each person, they choose Keep or Revoke and can leave a comment. Only the assigned reviewer or an admin can decide.
- Close it
Revoked items lose the role immediately. Close the review when every item is decided; progress is shown as you go.
Every request, decision and change is recorded, so you can show an auditor who had access, who approved it and when it was last checked.