Entitlement lifecycle
Each entitlement has a status that reflects where it is in the provisioning lifecycle.Viewing entitlements
Navigate to Settings > Applications > Entitlements tab to see all active and historical entitlements across your applications.Use the filters to narrow results by application, access level, status, user, or workspace. Each row shows the user, application, access level, status, created date, and expiration.Extending entitlements
When access has a duration set by the access policy, you can extend it before or after expiration. Extension creates a new entitlement record linked to the original for lineage tracking. The extended entitlement inherits the same application and access level.Revoking entitlements
Revoke access by selecting an active entitlement and choosing Revoke. You can add an optional revoke note for the audit trail.- Synced applications: triggers deprovisioning via the IdP integration, removing the user from the group or application.
- Manual applications: marks the entitlement as deprovisioned. A human must remove the actual access in the target system.
Manual provisioning
For applications with a manual provisioning method, entitlements require a human to grant access. Authorized provisioners (application owner, ticket assignee, workspace admins, and org admins) can mark entitlements as provisioned.Manual provisioning prompts appear in two places:- On the access request ticket, where any authorized provisioner can mark the entitlement as provisioned.
- In Slack, as a direct message to the ticket assignee. When a manual entitlement moves to Processing, Ravenna DMs the assignee an “Access ready to provision” message with a Provision access button. Clicking it marks the entitlement provisioned without leaving Slack, and the message updates to confirm.
The Slack DM goes to the ticket assignee. If the ticket is unassigned, the prompt only appears on the ticket itself, so make sure manual access requests get routed to an owner.
Ticket closure
When every access request on a ticket reaches a provisioned state, Ravenna moves the ticket to Done automatically. This applies whether provisioning happened through an identity provider or was confirmed manually, and it also applies when only some of the requested access could be granted.You do not need a workflow to close access request tickets.Workflow triggers
The Entitlement Status Changed trigger fires when an entitlement changes status. Configure it to trigger on one or more statuses to notify requesters, alert IT on failures, or fan out across multiple outcomes.Learn about workflow triggers