IDENTITY GOVERNANCE · LAB
Request, approve, fulfil and confirm access, and see what the tenant cannot record
Plan the catalog request flow your tenant will run, then carry out a request by hand with separate approvers and a fulfiller, confirm the access from the directory, and write the trail the tenant cannot hold.
PlannedUses your lab tenant
The lesson
Builds on: Searching a directory with LDAP.
New to the labs? Start with the lab toolkit and the shared cast and names every lab uses.
Planned. The core of this lab waits on platform features that are not built yet. The planned walkthrough shows exactly how it will run; Do today is a real exercise you can do now.
- G23 Access requests and approvals, access reviews, JIT or temporary access
Setup
The lesson's request is for a sensitive research database. Here it is the print order archive: past print orders, including customers' delivery addresses. Ava asks for it, Cora approves as her manager, Mia approves as the archive's owner, and Ben fulfils.
Open a bash shell and set the variables and helpers from the directory lab, plus
READER_IDandREADER_SECRETforlab-scim-reader, and look up Ava:export AVA=$(scim -G "$SCIM/Users" --data-urlencode 'filter=userName eq "[email protected]"' | jq -r '.Resources[0].id').Make sure Ben, Cora and Mia can sign in (passwords set on Users), and that Cora and Mia hold no management roles.
Planned: once G23 exists, groups gain catalog fields (description, owner, sensitivity, approval chain, longest duration) and can be marked requestable, and tenant users get a request page at
$ISSUER/account/access.
Planned walkthrough
As administrator, create the group
lab-tmp-print-archiveand mark it requestable: description "Read past print orders, including customers' delivery addresses. No changes and no exports.", owner Mia, sensitivity High, approvals "manager, then owner", longest duration 180 days.Ava signs in at
$ISSUER/account/access, searches for "archive", and requests it with the reason "Reviewing reprint complaints for the moderation team. I need to read past orders for the affected albums." and 90 days. Audit records the submission with the reason and requested end date.The tenant checks the request against separation rules, then routes it to Ava's
managerfrom the enterprise extension, Cora, who approves with a note.It routes on to the owner, Mia, who approves with a note. Fulfilment adds the membership, reads it back from the directory, and marks the request "Fulfilled and confirmed" with the removal scheduled for the end date.
Mia requests the same item for herself. The owner step skips Mia and routes to a deputy owner, and the skip is recorded.
Cora delegates her approvals to Ava for two weeks. Ava's own renewal routes past Ava to Cora's manager, because the approver is compared with the requester every time a request is routed.
On the end date, the tenant removes Ava's membership by itself and records the expiry against the request.
Do today
Every tenant action below is real. The request and approvals live in your notes, because the tenant has nowhere to hold them, and that gap is part of the lesson.
Write the catalog entry. In your notes, fill name, technical name (
lab-tmp-print-archive), what it allows, intended for, owner (Mia), sensitivity, approvals and longest duration, as in the lesson's table. Create the group in Groups.
Why it matters: this is "Asking for something specific". The entry tells the requester and the approvers what will happen before anything is submitted.
Separate deciding from doing. In Roles, create
lab-tmp-access-fulfilmentwithtenant.users.read,tenant.groups.readandtenant.groups.update, and assign it to Ben. Cora and Mia stay without management roles: they decide, they do not change access.The request. In your notes, Ava requests the item with the reason from Planned walkthrough step 2 and a 90-day duration. Write the end date.
Why it matters: this is "A reason and an end". A specific reason lets approvers judge now and lets a reviewer judge later; the end date is set at the start, not remembered later.
The approvals. In your notes, Cora approves as manager, then Mia as owner, each with a time and a one-line note. Nothing in the tenant can hold either decision.
Why it matters: this is "Who approves". Each approver answers a different question: does the job need it, and is it right for this resource.
Fulfilment. In a private window, sign in at
$ISSUER/manageas Ben and add Ava tolab-tmp-print-archive. Audit recordstenant.groups.memberswith Ben as actor.Confirmation from the target. Read the access back with the read-only client.
export TOKEN=$(token_for "$READER_ID" "$READER_SECRET" "$SCIM_SCOPE.read")
scim -G "$SCIM/Groups" --data-urlencode "filter=displayName eq \"lab-tmp-print-archive\" and members[value eq \"$AVA\"]" | jq .totalResults
export TOKEN=$(token_for "$CLIENT_ID" "$CLIENT_SECRET")
The answer is 1. Record "confirmed" in your notes with the Audit event ID from step 5.
Why it matters: this is "Fulfilment". A request is complete when the access exists in the target and has been checked, not when someone says so.
Where self-approval slips through. As Ben, add Ben to the group. It succeeds.
Why it matters: the fulfiller could also decide. Only a request engine that compares requester and approver every time it routes a request stops this, which is what Planned walkthrough steps 5 and 6 add.
What the record lacks. Open the Audit event from step 5: actor, subject, time and outcome. No reason, no approvers, no end date. Write the lesson's decision trail for the request by hand, and mark which lines came from the tenant.
Why it matters: this is "When approval stops meaning anything". An approval nobody can see later looks exactly like no approval at all.
Break it
As Ben, open the group's Members dialog and leave it open. In your own window, remove
tenant.groups.updatefromlab-tmp-access-fulfilment. Ben now removes himself from the open dialog: refused withaccess_denied, and Audit recordstenant.groups.membersrejected. Fulfilment needs the permission; approval, today, needs nothing at all.
Restore: add tenant.groups.update back to lab-tmp-access-fulfilment.
Check your work
This lab has no automated checks until its request steps exist. In Audit, Source User directory, look for:
tenant.roles.createandtenant.users.management_roles.assignfor Ben (Do today step 2)tenant.groups.membersby Ben for Ava, then for Ben (steps 5 and 7)tenant.groups.membersrejected withaccess_denied(Break it)scim.groups.searchbylab-scim-reader(step 6)
Cleanup
Remove Ben from
lab-tmp-print-archive, then remove Ava at the end date you chose, or now, and delete the group.Remove
lab-tmp-access-fulfilmentfrom Ben and delete the role.
Missing infrastructure
G23: the tenant has no access catalog, no requests with a reason and duration, no approval routing from the
managerattribute and the group owner, no self-approval or delegation check at routing time, no automatic fulfilment with read-back confirmation, no scheduled expiry, and no request or approval events in Audit. Once they exist, the Planned walkthrough replaces your notes, and Do today step 8's decision trail comes from the tenant itself.