An access request management app for IT teams managing temporary application access. Check requested roles and duration against application policy, collect manager, owner and conditional security reviews, and track manual provisioning, periodic access review and revocation evidence.

Access desk connects request intake, review decisions and access assurance in one workspace. Applications define allowed roles, maximum access duration and a security reviewer. Restricted or privileged requests add a security responsibility. Decisions apply to a specific scope revision; revising the role, dates, class or justification requests fresh decisions while retaining earlier evidence. Staff record provisioning checks after working in the source system and can periodically confirm continued need or request revocation. The English desktop pilot includes fictional ToolJet Database data. Public download and deployment await export and clean-install validation.
Built for IT service teams coordinating employee application access with managers and application owners.
Keep application policy, current review decisions and the external access handoff connected.
Open pending reviews and fulfillment handoffs. See grants needing periodic review or removal alongside application coverage.
Create a request with a role, business justification, start and end dates, and standard or privileged class. Filter by stage, class and review attention.
Record current-scope reviews, approve or reject, verify manual provisioning checks, revise scope, cancel pending work and record periodic access reviews or removal.
Maintain owners, sensitivity, security reviewers, allowed roles and maximum access duration. Pause intake when an application should not accept requests.
Requested roles and access duration must satisfy the current application policy. Restricted or privileged access adds Security to the manager and application-owner responsibilities.
Approval checks that every required responsibility has approved the current scope revision. Revising scope resets decisions and archives the previous scope and review evidence. Legacy requests require scope confirmation before new approval.
Manual provisioning records an operator, source-system evidence and confirmation that role and expiry match the approval. Restricted or privileged access additionally requires recorded MFA verification. Activation before the start date is blocked.
Periodic access reviews record continued need or a revocation handoff. Expired access cannot be retained. Operators record removal evidence after completing the action in the source system; cancelling an unprovisioned request retains its history.
The pilot uses 2 tables with fictional records. No external database is needed to explore the source app.
| Table | Sample data | What it stores |
|---|---|---|
| Applications | 6 sample applications | Application owners, sensitivity, intake availability and optional role, duration and security-review policies. |
| Access requests | 13 sample requests | Employee requests across review, approved, active and revocation stages, with scope revisions, assigned decisions and access assurance evidence. |
No identity-provider integration, automated provisioning, automatic account expiry, notifications or file uploads are included. Reviewers and operators are manually recorded; identity, independent reviewers and server-enforced role authorization are not verified. Policy and revision checks coordinate work in this app and do not secure external systems. Database uniqueness constraints and loaded-data prechecks cover references and application names; case-normalization behavior across concurrent sessions is unverified. The pilot loads up to 1,000 rows per table and blocks writes at that limit. Reopen a selected request after hard reload. Export portability and clean installation remain unverified.
This design is a starting point. Describe the look you want, add your logo and brand colors, or ask for new features in a prompt. Use the starter prompt to build your own version in the ToolJet AI builder, or use a suggested prompt to modify an app you already have. Review and test the result.
Suggested prompts describe changes you can request. Additional features and translations still need to be built and tested.
Choose ToolJet Cloud, or download the application package to import into your self-hosted instance once the template is released.
Explore the sample records in ToolJet Database, then add your records and configure the workflow for your team.
Describe your preferred design, branding, and new features in the AI builder. Test your workflow, then share your app with the people who need it.
It includes policy-aware intake, scope revisions, manager and owner reviews, conditional Security review, approval decisions, manual fulfillment checks, periodic access reviews and revocation evidence.
No. Staff change access in the source system and record the operator and evidence here. Review dates and access end dates highlight work; they do not run external account changes.
Restricted applications and requests marked privileged require an additional Security decision. The application policy provides the assigned security reviewer.
Revising an unprovisioned request archives the prior scope and decisions, increments the scope revision and resets assigned decisions. Approval requires reviews for the current revision.
Yes. Record continued need and the next review date, or request revocation. Expired grants cannot be retained, and removal still requires a separate operator evidence record.
No. The app records names and responsibilities manually. Enforced identity, role permissions and separation of duties need additional implementation and testing.
Use the starter prompt or follow-up prompts to change branding, layout, fields and workflow. Integrations, language support and authorization controls require implementation and testing.
The local pilot uses fictional ToolJet Database data. Public deployment and download remain disabled until export and clean installation are validated.