Build and manage your application catalog with access levels, provisioning methods, and identity provider integrations.
Applications represent the external tools and services your organization uses. By defining applications in Ravenna with their corresponding access levels and provisioning methods, you create a structured catalog that supports automated access requests.
Go to Settings > Applications in the left sidebar.
2
Add application
Click Add Application to create a new application entry.
3
Fill basic information
Provide the application details:
Name: Display name for the application.
Domain: The application’s web domain (optional).
Details: Rich text notes about the application (optional). These notes appear in hover cards when users view the application in ticket custom fields.
Owner: User or user group responsible for managing this application. Selecting a group lets the entire group act as the owner for routing and fallback purposes.
Approver: User or user group responsible for approving access requests. When a group is selected, every member is treated as an approver. If no approver is set, the application owner is used as a fallback.
Post provisioning message: Optional rich text message sent to the requester after access is granted. Use it to share login instructions, onboarding resources, or follow-up steps.
Workspaces: Select which workspaces can surface this application in request forms.
4
Configure access levels
Add access levels to define the permission tiers available for this application. See Access levels below.
Applications can be automatically imported from your identity provider rather than created by hand.When you connect Okta, Google Workspace, or Microsoft Entra ID, Ravenna discovers the applications in your IdP and adds them to your catalog. Each synced application shows the integration name as its Source.What syncing means in practice:
The application name and image stay in sync with the IdP. You cannot edit them directly in Ravenna.
You cannot delete a synced application while the integration is active.
You can set a Display Name to override the IdP name shown to users. The original name is preserved for sync purposes and appears alongside the display name in the format Display Name (Original Name).
Use display names to make application names more recognizable to your users without affecting how the IdP integration works.
The provisioning method on an application (or access level) controls how access is granted after a request is approved.
Group
Provision access by adding the user to a group in your identity provider. After approval, Ravenna adds the user to the mapped IdP group, which then grants access to the application through the IdP’s own assignment rules.Supported by: Okta, Google Workspace, Microsoft Entra IDUse this when your IdP manages application access through group membership.
Application
Provision access by assigning the user directly to the application in the IdP. Rather than adding the user to a group, Ravenna adds them to the application itself using the identity provider’s application assignment API.Supported by: Okta onlyUse this when direct application assignment is preferred over group-based access in your IdP.
Manual
No automated provisioning. After approval, an authorized provisioner must manually grant access in the target system and then mark the entitlement as provisioned in Ravenna.Authorized provisioners for a manual access level include the application owner, the ticket assignee, and workspace admins.No IdP required. Use this for applications that are not connected to an identity provider, or where automated provisioning is not possible.
Workflow
Provisioning is handled by a workflow action. After approval, a configured workflow runs and performs whatever provisioning steps you define, including calling external APIs, sending notifications, or chaining multiple actions.No IdP required. Use this for custom provisioning logic that goes beyond standard IdP operations.
Access levels define the permission tiers available within an application. Each level represents a specific set of capabilities a user can be granted, and each has its own provisioning method, approvers, and optional IdP group mapping.
Archive access levels you no longer want users to request. Archived levels are hidden from request forms but retain their approval history and IdP mappings for audit purposes.
1
Open the access levels tab
Go to Settings > Applications, select the application, and open the Access Levels tab.
2
Archive the level
Select the access level row and use the Archive action. To archive several at once, select multiple rows and use the Archive bulk action.
To restore an archived access level, filter the table by Archived status, select the level, and use the Unarchive action.
Archiving an access level does not revoke access already granted through it. Existing tickets, approval history, and IdP mappings are preserved. To revoke previously granted access, handle the deprovisioning separately in your identity provider.
Assignment strategies control how approvers are assigned to access request tickets for a given access level.
Assignment strategies are the older approach to approver routing. When your access levels use access policies, approval routing comes from the policy’s approval template instead, and the access level form shows an Access Policy selector in place of the approver and assignment strategy fields.
Auto
Automatically approves the request without human intervention. The system bot is assigned as the approver and the request is approved immediately.Use this for low-risk applications or access levels where automatic approval is acceptable, such as dev environments or self-service tools.
All
Assigns all specified approvers to the ticket. Any one of them can approve the request.Use this when multiple people are qualified to approve and you want the fastest possible response from the available pool.
Round Robin
Distributes approval requests evenly across the approver pool. Only one approver is assigned per request, rotating through the list to balance workload.Use this when you want fair distribution of approval responsibilities across a team.
Configure different assignment strategies for different access levels within the same application. For example, Member access might use “Auto” for immediate approval while Admin access uses “Round Robin” to distribute the review work.
Map access levels to groups in your identity provider for automated provisioning. After an access request is approved, Ravenna can automatically add the user to the mapped group or application.Not all providers support the same provisioning methods:
Connect your Okta integration and map access levels to Okta groups or applications. Okta is the only provider that supports both group-based and direct application assignment provisioning.
1
Connect the Okta integration
Go to Settings > Integrations and configure your Okta connection.
2
Map access levels
When creating an access level, select the corresponding Okta group from the dropdown.
3
Set the provisioning method
Choose how the access level provisions once a request is approved:
Group: Ravenna adds the user to the mapped Okta group, which then grants application access through Okta’s assignment rules.
Application: Ravenna assigns the user directly to the Okta application without group membership.
Provisioning runs automatically after approval. No workflow is required.
Connect your Google Workspace integration and map access levels to Google Groups. Google Workspace supports group-based provisioning only. Direct application assignment is not available through this integration.
1
Connect the Google Workspace integration
Go to Settings > Integrations and configure your Google Workspace connection.
2
Map access levels
When creating an access level, select the corresponding Google Group from the dropdown.
3
Set the provisioning method
Choose Group. After approval, Ravenna adds the user to the mapped Google Group, which grants access to connected Workspace apps and shared resources. No workflow is required.
Connect your Microsoft Entra ID integration and map access levels to Entra groups. Entra supports group-based provisioning only. Direct application assignment is not available through this integration.
1
Connect the Entra ID integration
Go to Settings > Integrations and configure your Microsoft Entra ID connection.
2
Map access levels
When creating an access level, select the corresponding Entra group from the dropdown.
3
Set the provisioning method
Choose Group. After approval, Ravenna adds the user to the mapped Entra group. No workflow is required.
Archive applications you no longer want users to request access to. Archived applications are hidden from request forms by default, but their access levels and approval history remain intact for audit purposes.
1
Open the application
Go to Settings > Applications and select the application you want to archive.
2
Archive
Use the Archive action in the application’s details. A confirmation appears before the application is archived.
To archive multiple applications at once, select them from the applications table and use the Archive bulk action.To restore an archived application, filter the table by Archived status, select the application, and use the Unarchive action.
While an application is archived, Ravenna blocks changes to its access levels and rejects new access requests tied to it. Unarchive the application before resuming access request activity.
Archiving does not revoke any access already provisioned through the application. To revoke previously granted access, handle the deprovisioning separately in your identity provider.
Delete an application to permanently remove it from your catalog.
Deletion is permanent and cannot be undone. If you need to preserve approval history, ticket references, or audit trails, archive the application instead.
1
Open the application
Go to Settings > Applications and select the application you want to delete.
2
Delete
Use the Delete action in the application’s details. A confirmation dialog appears before the application is permanently removed.
Deleting an application does not revoke any access already provisioned through it. Handle any deprovisioning separately in your identity provider.
Export your application catalog to CSV for audits, reporting, or offline review. The export reflects any search, sort, or filter you have applied in the applications table.
1
Open applications
Go to Settings > Applications.
2
Apply filters (optional)
Apply any filters you want included in the export. Only applications currently visible in the table are exported.
3
Export
Click Export in the toolbar. The file downloads as applications-export-<date>.csv.
Exports are capped at 10,000 applications per file. Use filters to narrow the list if your catalog exceeds that limit.
Last modified on August 5, 2026
Was this page helpful?
⌘I
Assistant
Responses are generated using AI and may contain mistakes.