Access Request and Approval Form
Purpose
Use this form to request, approve, change, or remove access to company systems, applications, data, shared folders, administrative functions, or other restricted resources.
The objective is to make sure access is granted for a clear business reason, approved by the right person, limited to what is needed, and recorded for later review.
Request Information
Request ID: ____________________
Request date: ____________________
Requested by: ____________________
Department: ____________________
Manager: ____________________
User receiving access: ____________________
Employment or contractor status: ____________________
Type of Request
Select one:
- New access
- Access change
- Additional access
- Temporary access
- Privileged access
- Vendor or contractor access
- Access removal
- Other: ____________________
System or Resource
System, application, folder, data set, or service:
System owner:
Business owner:
Access Requested
Describe the access required:
Examples:
- Standard user access
- Read-only access
- Edit access
- Finance approval access
- Payroll access
- Customer data access
- Administrator access
- Shared mailbox access
- Cloud console access
- Remote access
- Vendor portal access
Business Reason
Explain why the access is required:
The request should explain the business activity the user needs to perform.
Access Duration
Select one:
Permanent while role requires it
Temporary
Temporary start date: ____________________
Temporary expiry date: ____________________
Temporary access should have an expiry date wherever practical.
Risk Classification
Is this access high-risk?
Yes / No
High-risk access may include:
- Administrator access
- Finance or payment approval
- Payroll
- Sensitive employee data
- Sensitive customer data
- Cloud administration
- Backup administration
- Security system administration
- Source code or production systems
- Vendor or MSP administrative access
If high-risk, describe:
Security Requirements
Confirm where applicable:
-
MFA required: Yes / No
-
Approved device required: Yes / No
-
VPN or controlled remote access required: Yes / No
-
Separate admin account required: Yes / No
-
Additional logging required: Yes / No
-
Training required before access: Yes / No
Other conditions:
Manager Approval
I confirm that the requested access is required for the user’s role.
Manager:
Decision:
- Approved / Rejected
Date:
System or Data Owner Approval
I confirm that the requested access is appropriate for this system or data.
Owner:
Decision:
- Approved / Rejected
Date:
Additional High-Risk Approval
Required:
- Yes / No
Approver:
Decision:
- Approved / Rejected
Date:
Access Implementation
Implemented by:
Implementation date:
Account or role assigned:
MFA confirmed:
- Yes / No / Not Applicable
Temporary expiry configured:
- Yes / No / Not Applicable
Evidence or ticket reference:
Verification
Confirm:
-
Access matches the approved request.
-
No unnecessary permissions were added.
-
Security requirements were applied.
-
Temporary access has an expiry where applicable.
-
User was informed of relevant responsibilities.
Verified by:
Date:
Review or Removal
Next review date:
Access removed or changed date:
Reason:
Practical Rule
Access should have a clear business reason, an appropriate approval, and only the permissions required to perform the work.