Skip to main content
An entitlement is a record that tracks the full lifecycle of an access grant for a user to an application or user group. Ravenna creates an entitlement when an access request is approved, then tracks it through provisioning, active use, expiration, revocation, or failure. Entitlements give you a complete picture of access state, not just what is currently active, but also what failed, was revoked, or expired.

Entitlement lifecycle

Each entitlement has a status that reflects where it is in the provisioning lifecycle.

Viewing entitlements

Navigate to Settings > Applications > Entitlements tab to see all active and historical entitlements across your applications.Use the filters to narrow results by application, access level, status, user, or workspace. Each row shows the user, application, access level, status, created date, and expiration.

Extending entitlements

When access has a duration set by the access policy, you can extend it before or after expiration. Extension creates a new entitlement record linked to the original for lineage tracking. The extended entitlement inherits the same application and access level.

Revoking entitlements

Revoke access by selecting an active entitlement and choosing Revoke. You can add an optional revoke note for the audit trail.
  • Synced applications: triggers deprovisioning via the IdP integration, removing the user from the group or application.
  • Manual applications: marks the entitlement as deprovisioned. A human must remove the actual access in the target system.
Revoking an entitlement for a synced application immediately removes the user’s access in the identity provider.

Manual provisioning

For applications with a manual provisioning method, entitlements require a human to grant access. Authorized provisioners (application owner, ticket assignee, workspace admins, and org admins) can mark entitlements as provisioned.Manual provisioning prompts appear in two places:
  • On the access request ticket, where any authorized provisioner can mark the entitlement as provisioned.
  • In Slack, as a direct message to the ticket assignee. When a manual entitlement moves to Processing, Ravenna DMs the assignee an “Access ready to provision” message with a Provision access button. Clicking it marks the entitlement provisioned without leaving Slack, and the message updates to confirm.
After granting access in the external system, the provisioner marks the entitlement complete in Ravenna through either path.
The Slack DM goes to the ticket assignee. If the ticket is unassigned, the prompt only appears on the ticket itself, so make sure manual access requests get routed to an owner.

Ticket closure

When every access request on a ticket reaches a provisioned state, Ravenna moves the ticket to Done automatically. This applies whether provisioning happened through an identity provider or was confirmed manually, and it also applies when only some of the requested access could be granted.You do not need a workflow to close access request tickets.

Workflow triggers

The Entitlement Status Changed trigger fires when an entitlement changes status. Configure it to trigger on one or more statuses to notify requesters, alert IT on failures, or fan out across multiple outcomes.
Learn about workflow triggers
Last modified on August 5, 2026