Documentation Index

Fetch the complete documentation index at: https://docs.senhasegura.io/llms.txt

Use this file to discover all available pages before exploring further.

How to create an access request

Prev Next

This document provides information on how to create administrative access requests in the My requests screen on Cloud Entitlements. Users can create access requests to actions for which an active workflow will require approval before execution.

Info
  • Depending on your user role, the path to access this screen may differ.
  • Active workflows block the immediate execution and route requests to the designated approvers.

Requirements

User with one of the following roles:

  • Cloud Entitlements - Operator: provides exclusive, restricted access to the My requests screen. Operators do not have access to other platform menus.
  • Cloud Entitlements - Basic User: provides access to create requests via the Cloud Entitlements navigation menu.

Create an access request

  1. Access the Cloud Security platform.
    Info

    If you have the Cloud Entitlements - Operator role, you will be automatically redirected to the My requests screen and can skip to step 4.

  2. Access the Cloud Entitlements product.
  3. In the Requests menu, click My requests.
  4. On the My requests screen, click + New request.
  5. On the New request panel, complete the following fields:
    1. Request type *: select the functionality or action you want to request access to. The options are: JIT, Access key, and New user.
    2. Provider *: select the provider you need to access. The options are: AWS, GCP, Azure, and OCI.
    3. Reason *: enter a detailed justification for the access request.

Depending on the request type selected, the panel will display specific fields. Proceed to the corresponding section to finish your request:

Request JIT access

If you selected JIT as the request type, complete the following fields in the JIT details section:

  1. Policy *: select the permissions policy you want to apply. The available options correspond to the selected provider.
  2. Account *: select the target cloud account. The available options correspond to the selected provider.
  3. Entity *: this field is displayed after you select an account. Select the target entity whose privileges you wish to assume.
  4. Click Save.

Request an access key

If you selected Access key as the request type, complete the following fields in the Access key details section:

  1. Account *: select the target cloud account. The available options correspond to the selected provider.
  2. Entity *: this field is displayed after you select an account. Select the target entity (user, role, or service account) for which the access key will be generated.
  3. Click Save.

Request a new user

If you selected New user as the request type, complete the following fields in the New user details section:

  1. Username *: enter the username for the new user.
  2. User email: enter the email for the new user. This field is mandatory when Azure is selected as the provider.
  3. Account *: select the target cloud account where the user will be created. The available options correspond to the selected provider.
  4. Has console access: toggle to grant or deny access to the web management console.
  5. Policies: select the permissions policies to attach to the new user.
  6. Click Save.

The newly created request will be displayed on the My requests report screen with the status Pending, and the system will send a notification to the designated approver. You can click on the request to access the details screen.

Info

If a communication failure occurs with the cloud provider after your request is approved, the status will change to Execution error. In this scenario, the system does not allow automatic retries, and you must create a new request.

Attention

For access key requests, once the status changes to Approved, the requested key can only be displayed once on the request details screen. Copy and store it securely, as it will be permanently hidden after you close or refresh the page.