Sentinel Help Center
  • Sentinel Overview
    • Dashboard
    • Environments
    • User Hub
    • Requests
    • Reports
  • Installation & Updates
    • Sentinel Shortcuts [From PS]
    • Sentinel VM Requirements
    • Host Server Setup RHEL/CentOS 8
    • Host Server Setup RHEL/CentOS 9
    • Sentinel Server Update
    • Oracle Database Account
    • PostgreSQL Backups
  • Settings
    • Sentinel Accounts
    • Databases
    • System Settings
    • Single Sign-On
    • Access Request Settings
    • Role Groups
    • Role Approvers
    • Custom Forms
    • Sensitive Data Settings
    • Security Log
  • Security Administration
    • Menu Functions
    • Direct Access
    • Users
      • User Access Updates
      • User Profile Features
    • Roles
      • Role Updates
      • Role Features
    • Permission Lists
      • Permission List Updates
      • Permission List Features
    • Dynamic Security
    • Temporary Access
    • Fluid Security
    • Security Matrix
    • Compare Reports
  • Security Reports
    • Security Reports Setup
    • Page Analysis
    • User Access
    • Role Access
    • Permission List Access
    • Query Analysis
    • Compare Users
    • PeopleTools Access
    • Portal Menus
  • Audit Review
    • Audit Review Setup
    • Privileged Access
    • Sensitive Data
    • Segregation of Duties
    • Correction Access
    • Restricted Roles
    • Role Changes
    • Notifications
    • Manager Reports
  • Access Requests
    • Implementation Guide
    • Submit New Request
    • Review & Approve Requests
    • Workflows & Routing
    • Apply Changes
  • Resources
    • User Training Guide
    • Policies
      • Policy Overview
      • Data Privacy
      • Cloud Security
      • Software Development
      • Disaster Recovery
      • Service Level Agreement
      • Employees
Powered by GitBook
On this page
  • Project Stages
  • Sentinel Workflow Stages
  • User Types
  • Configuration Settings
  1. Access Requests

Implementation Guide

Access Request - Module Implementation Guide

PreviousAccess RequestsNextSubmit New Request

Last updated 1 year ago

Access Requests provides a platform to , , and in PeopleSoft. It streamlines requesting access and eliminates email or paper requests.

Managers and functional leads can view an employee’s current PeopleSoft access and submit a request for roles to be added or removed.

Implementing the Access Requests module requires proper planning, configuration, and training to ensure that Sentinel is configured to support your business process. The following document outlines the process and setup options to consider for implementation:

Current Process

Document current business process.

Sentinel

Review Sentinel functionality and configuration options.

Gap Analysis

Identify gaps, limitations, and required configurations.

Dynamic Security

Determine if dynamic security jobs can be used to reduce repetitive role assignments.

Identify Users

Identify Requesters, Approvers, and Request Administrators. - Define - Define - Define

Define Workflows

Identify criteria and approvers for existing workflows.

Define Settings

Review configuration settings and determine if any additional setup is required.

Create Workflows

Build test workflows in Sentinel. - Settings / Users / Accounts / Security Profiles.

Create Test Accounts

Create user accounts and assign security profiles to Requesters and Approvers. - Settings / User Accounts

User Training

Train test Requesters and Approvers on the AR module.

Test User Security

Verify test users can log in with password/SSO. - Submit Request - Review / Modify - Approve / Deny - Admin Appy Changes

Test Workflows

Verify the correct approvers are selected for the workflow criteria.

Sentinel Workflow Stages

The Requests module can be used without pre-configured workflows but requires the requesters to select the approvers manually. Workflows can be created to support various approval requirements and eliminate the need for requesters to select approvers.

Create a New Request for a security change in PeopleSoft.

1. Select User

Search and select an existing User or create a new user.

2. Select Roles

Select Roles to be added/removed or leave blank.

3. Select Permissions lists

Select row security or profile permission lists.

4. Add Attachments

Add file or image attachment.

5. Enter Comments

Comments can be used when requesting security or to add notes.

6. Workflow

Manually select Reviewer and Approvers, or use default options based on Workflow jobs.

Assign a Reviewer to review the request before it is sent for approval. (This is an optional stage of the workflow.)

Reviewer

Reviewers can review and modify requests, including adding or removing roles. They can only view the user requests they receive (are assigned to).

Assign an Approver or Backup Approver (Optional) to approve or deny a request.

Approver 1

Approvers can only approve or deny requests with a reason. They cannot make changes to the request.

Backup Approver (optional)

Backup Approvers can approve or deny requests if Approver 1 is unavailable. They cannot make changes to the request.

Apply approved security changes to PeopleSoft.

Update PeopleSoft

Only Sentinel or Access Request Administrators can apply approved changes to PeopleSoft. They can also make changes to a request if needed or re-route for additional approval.

Auto-Provision Approved Requests

User Types

Users given access to the Request module can only see the requests they send or receive. Sentinel or Access Request Administrators can see all requests and make changes to the permissions or approvers.

#

Settings

Create

Edit

Approve

Comments

1

Requester

A person who is allowed to create a ticket.

✔️

✔️

Requesters can only view tickets sent or received.

2

Reviewer (Optional)

A person who is allowed to modify the request and select roles before the ticket is sent for approval.

✔️

3

Approver

The person who is designated on the request ticket to approve/deny access.

✔️

Approver cannot modify access on tickets but can change approvers.

4

Backup Approver (Optional)

A secondary person who is designated on the request ticket to approve/deny access.

✔️

5

Notify

Send to a group mailbox to notify multiple users.

The notify field is used for group mailboxes.

Configuration Settings

Configurations provide additional options for setting up the request module. Some items will require additional setup before they can be used.

#

Settings

Req / Opt

Description

1.1

Request users can be restricted to viewing only specific users or roles.

Required

*Security profiles can be configured to grant a user View or Update access to Sentinel modules, pages, and reports.

1.2

Automatically create new user accounts.

Optional

SSO can be used to authenticate users and automatically create new user accounts.

2

A request admin can view and edit all tickets.

Optional

The request admin is traditionally a functional lead or analyst who assists in verifying requested access or selecting the appropriate roles before the ticket is sent for approval.

3

Create default approval routings.

Optional

Automatically display preselected approvers based on org criteria.

4

Specify approvers for selected Roles.

Optional

Role approvers can be defined for roles that require approval from specific people.

5

Training Requirement

Ability to mark roles that require training certification before a role can be assigned.

Optional

Roles that require training will not be assigned until the training is marked as completed.

6

Automatically apply changes to PeopleSoft.

Optional

Approved requests can be automatically applied to PeopleSoft.

7

Restrict users to only seeing specific PS roles.

Optional

Create Static or Dynamic Role Groups to limit the roles that a Request user can see.

To allow access to view all user requests, a Reviewer must be assigned Access Request Admin privileges on their .

Approved requests can be automatically applied to PeopleSoft using

- Select a security profile to grant a user access to a PS environment.

Access to Users can be restricted to specific Business Units and/or Departments.

- Access to Roles can be restricted using static or dynamic role groups.

Submit
Approve
Apply Security Changes
Security Profiles
User Access
Role Access
Sentinel Account - Admin Menus
auto-provisioning settings.
User Security
Environment Access
User Access -
Role Access
Single Sign-On
Access Request Admin
Workflows
Role Approvers
Auto-Provisioning
Role Groups