# Implementation Guide

**Access Requests** provides a platform to [**Submit**](/sentinel-help-center/access-requests/submit-new-request.md), [**Approve**](/sentinel-help-center/access-requests/review-and-approve-requests.md), and [**Apply Security Changes**](/sentinel-help-center/access-requests/apply-changes.md) in PeopleSoft. It streamlines requesting access and eliminates email or paper requests.

Managers and functional leads can view an employee’s current PeopleSoft access and submit a request for roles to be added or removed.

## [Project Stages ](#user-content-fn-1)[^1]

Implementing the Access Requests module requires proper planning, configuration, and training to ensure that Sentinel is configured to support your business process. \
\&#xNAN;*The following document outlines the process and setup options to consider for implementation:* &#x20;

{% tabs %}
{% tab title="1. Requirements" %}

#### **Current Process**

Document current business process.&#x20;

#### **Sentinel**&#x20;

Review Sentinel functionality and configuration options.&#x20;

#### **Gap Analysis**

Identify gaps, limitations, and required configurations.&#x20;

#### Dynamic Security&#x20;

Determine if dynamic security jobs can be used to reduce repetitive role assignments.
{% endtab %}

{% tab title="2. Planning" %}

#### **Identify Users**

Identify Requesters, Approvers, and Request Administrators.\
\- Define [**Security Profiles**](/sentinel-help-center/settings/sentinel-accounts.md#security-profiles)\
\- Define [**User Access** ](/sentinel-help-center/settings/sentinel-accounts.md#user-access)\
\- Define [**Role Access**](/sentinel-help-center/settings/sentinel-accounts.md#role-access)

**Define Workflows**

Identify criteria and approvers for existing workflows.

#### **Define Settings**

Review configuration settings and determine if any additional setup is required.&#x20;
{% endtab %}

{% tab title="3. Development" %}

#### Create Workflows

Build test workflows in Sentinel. \
\- Settings / Users / Accounts / Security Profiles.

#### Create Test Accounts

Create user accounts and assign security profiles to Requesters and Approvers. \
\- Settings / User Accounts&#x20;
{% endtab %}

{% tab title="4. Testing" %}

#### User Training

Train test Requesters and Approvers on the AR module.

#### Test User Security

Verify test users can log in with password/SSO. \
\- Submit Request \
\- Review / Modify \
\- Approve / Deny\
\- Admin Appy Changes&#x20;

#### Test Workflows

Verify the correct approvers are selected for the workflow criteria.&#x20;
{% endtab %}
{% endtabs %}

## Sentinel Workflow Stages

The Requests module can be used without pre-configured workflows but requires the requesters to select the approvers manually.  Workflows can be created to support various approval requirements and eliminate the need for requesters to select approvers.

{% tabs %}
{% tab title="1. Submit" %}
*Create a New Request for a security change in PeopleSoft.*&#x20;

**1. Select User**&#x20;

Search and select an existing User or create a new user. &#x20;

#### **2. Select Roles**

Select Roles to be added/removed or leave blank.

#### **3. Select Permissions lists**&#x20;

Select row security or profile permission lists.

#### **4. Add Attachments**

Add file or image attachment.

#### **5. Enter Comments**&#x20;

Comments can be used when requesting security or to add notes.

#### **6. Workflow**&#x20;

Manually select Reviewer and Approvers, or use default options based on Workflow jobs.
{% endtab %}

{% tab title="2. Review (Optional)" %}
*Assign a Reviewer to review the request before it is sent for approval. (This is an optional stage of the workflow.)*

#### Reviewer

Reviewers can review and modify requests, including adding or removing roles. They can only view the user requests they receive (are assigned to).&#x20;

{% hint style="info" %}
To allow access to *view all user requests*, a Reviewer must be assigned Access Request Admin privileges on their [Sentinel Account - Admin Menus](/sentinel-help-center/settings/sentinel-accounts.md#admin-menus).
{% endhint %}
{% endtab %}

{% tab title="3. Approve" %}
*Assign an Approver or Backup Approver (Optional) to approve or deny a request.*

#### **Approver 1**

Approvers can only approve or deny requests with a reason. They *cannot* make changes to the request.&#x20;

#### **Backup Approver (optional)**

Backup Approvers can approve or deny requests if Approver 1 is unavailable. They *cannot* make changes to the request.&#x20;
{% endtab %}

{% tab title="4. Apply Changes" %}
*Apply approved security changes to PeopleSoft.*&#x20;

#### **Update PeopleSoft**

Only Sentinel or Access Request Administrators can apply approved changes to PeopleSoft. They can also make changes to a request if needed or re-route for additional approval.&#x20;

#### Auto-Provision Approved Requests&#x20;

Approved requests can be automatically applied to PeopleSoft using [**auto-provisioning settings.**](/sentinel-help-center/access-requests/apply-changes.md#auto-provisioning)
{% endtab %}
{% endtabs %}

## User Types

Users given access to the Request module can only see the requests they send or receive. Sentinel or Access Request Administrators can see all requests and make changes to the permissions or approvers.

<table data-header-hidden data-full-width="false"><thead><tr><th width="54"></th><th width="249"></th><th width="87"></th><th width="65"></th><th width="101"></th><th></th></tr></thead><tbody><tr><td><strong>#</strong></td><td><strong>Settings</strong></td><td><strong>Create</strong></td><td><strong>Edit</strong></td><td><strong>Approve</strong></td><td><strong>Comments</strong> </td></tr><tr><td>1</td><td><p><strong>Requester</strong></p><p>A person who is allowed to create a ticket.</p></td><td>✔️</td><td>✔️</td><td><br></td><td>Requesters can only view tickets sent or received.</td></tr><tr><td>2</td><td><p><strong>Reviewer (Optional)</strong></p><p>A person who is allowed to modify the request and select roles before the ticket is sent for approval.  </p></td><td><br></td><td>✔️</td><td><br></td><td><br></td></tr><tr><td>3</td><td><p><strong>Approver</strong></p><p>The person who is designated on the request ticket to approve/deny access.</p></td><td><br></td><td><br></td><td>✔️</td><td>Approver cannot modify access on tickets but can change approvers.</td></tr><tr><td>4</td><td><p><strong>Backup Approver (Optional)</strong></p><p>A secondary person who is designated on the request ticket to approve/deny access. </p></td><td><br></td><td><br></td><td>✔️</td><td><br></td></tr><tr><td>5</td><td><p><strong>Notify</strong></p><p>Send to a group mailbox to notify multiple users.</p></td><td><br></td><td><br></td><td><br></td><td>The notify field is used for group mailboxes.</td></tr></tbody></table>

## Configuration Settings&#x20;

Configurations provide additional options for setting up the request module. Some items will require additional setup before they can be used.

<table data-header-hidden data-full-width="false"><thead><tr><th width="69"></th><th width="225"></th><th width="124"></th><th></th></tr></thead><tbody><tr><td><strong>#</strong></td><td><strong>Settings</strong></td><td><strong>Req / Opt</strong></td><td><strong>Description</strong></td></tr><tr><td>1.1</td><td><p><a href="/pages/Z4djI6AOkDceUPB1TgYe"><strong>User Security</strong></a></p><p>Request users can be restricted to viewing only specific users or roles.</p></td><td>Required</td><td><p><a href="/pages/Z4djI6AOkDceUPB1TgYe#environments"><strong>Environment Access</strong> </a><strong>-</strong> Select a security profile to grant a user access to a PS environment.</p><p>*Security profiles can be configured to grant a user View or Update access to Sentinel modules, pages, and reports.<br></p><p><a href="/pages/Z4djI6AOkDceUPB1TgYe#user-access"><strong>User Access -</strong></a> Access to Users can be restricted to specific Business Units and/or Departments.</p><p></p><p><a href="/pages/Z4djI6AOkDceUPB1TgYe#role-access"><strong>Role Access</strong> </a><strong>-</strong> Access to Roles can be restricted using static or dynamic role groups. </p></td></tr><tr><td>1.2</td><td><p><a href="/pages/QwJwqyOORLuxZfgFq00O"><strong>Single Sign-On</strong></a></p><p>Automatically create new user accounts.</p></td><td>Optional</td><td>SSO can be used to authenticate users and automatically create new user accounts.</td></tr><tr><td>2</td><td><p><a href="/pages/Z4djI6AOkDceUPB1TgYe#admin-menus"><strong>Access Request Admin</strong></a></p><p>A request admin can view and edit all tickets. </p></td><td>Optional</td><td>The request admin is traditionally a functional lead or analyst who assists in verifying requested access or selecting the appropriate roles before the ticket is sent for approval.</td></tr><tr><td>3</td><td><p><a href="/pages/2N1q7Km4eMI6ayUcFQQk"><strong>Workflows</strong></a></p><p>Create default approval routings.</p></td><td>Optional</td><td>Automatically display preselected approvers based on org criteria. </td></tr><tr><td>4</td><td><p><a href="/pages/OrEwTLIY4XpaITN3iLEw"><strong>Role Approvers</strong></a></p><p>Specify approvers for selected Roles.</p></td><td>Optional</td><td>Role approvers can be defined for roles that require approval from specific people. </td></tr><tr><td>5</td><td><p><strong>Training Requirement</strong></p><p>Ability to mark roles that require training certification before a role can be assigned.</p></td><td>Optional</td><td>Roles that require training will not be assigned until the training is marked as completed. </td></tr><tr><td>6</td><td><p><a href="/pages/2N1q7Km4eMI6ayUcFQQk"><strong>Auto-Provisioning</strong></a></p><p>Automatically apply changes to PeopleSoft.</p></td><td>Optional</td><td>Approved requests can be automatically applied to PeopleSoft.</td></tr><tr><td>7</td><td><p><a href="/pages/Gvj9gJZSQNQSPNpfRBse"><strong>Role Groups</strong></a></p><p>Restrict users to only seeing specific PS roles.</p></td><td>Optional</td><td>Create Static or Dynamic Role Groups to limit the roles that a Request user can see.</td></tr></tbody></table>

[^1]:


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://help.sentinelsoftware.com/sentinel-help-center/access-requests/implementation-guide.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
