What you can do
Import and manage applications
Sync your application catalog from Okta, Google Workspace, or Entra ID. Define access levels with provisioning methods that map to IdP groups for automated granting.
Define access policies
Control who can request access, link approval templates, set duration options, and require business justification. Policies sit between users and access levels.
Track entitlements
Every approved request becomes an entitlement. Monitor active grants, handle extensions and revocations, and respond to provisioning failures.
Enable agent-assisted requests
Let your AI agent help users discover eligible applications, submit requests, and renew expiring access through conversation in Slack.
How it works
A user requests access to an application, either by submitting a form or asking the AI agent. Ravenna evaluates the access policy to confirm the user is eligible, then applies the linked approval template to route the request to the right approvers. Once approved, access is provisioned through your identity provider automatically.For applications without an identity provider connection, provisioning is manual: an authorized person grants access in the target system and confirms it in Ravenna.Key concepts
Applications
are the tools and services your organization manages access to. They can be synced from your identity provider (Okta, Google Workspace, Microsoft Entra ID) or created manually for tools outside your IdP.Each application has one or more access levels representing permission tiers, like Viewer, Editor, or Admin. Each access level specifies a provisioning method:Group and Application give you end-to-end automation with no workflow to build. Reach for Workflow only when provisioning needs custom logic the other methods cannot express.
Learn more about applications and access levels
Access policies
govern who can request each access level and under what conditions. A policy defines:- Eligibility based on user group membership
- Approval template for routing requests to the right approvers
- Duration options for how long access should last
- Business justification requirements
Learn more about access policies
Entitlements
An is a concrete access grant: a record that a specific user has been provisioned a specific access level on a specific application. Entitlements track status (provisioned, deprovisioned, failed), expiration dates, and the full history of how access was granted.Learn more about entitlements
Synced vs manual applications
Synced applications import from your identity provider. Their access levels map to IdP groups, so after approval Ravenna adds the user to the correct group and access flows through your existing assignment rules. Changes in the IdP sync back to Ravenna automatically.Manual applications are for tools not managed by an IdP. After approval, an authorized provisioner (the application owner, ticket assignee, or a workspace admin) grants access in the target system and confirms it in Ravenna. This is particularly valuable for bringing untracked tools under governance: teams often adopt SaaS products outside of IT’s visibility, and manual applications give you a formal request flow and audit trail for these tools without requiring an IdP connection.What is Shadow IT? Shadow IT refers to tools and services adopted by teams without IT’s knowledge or approval. Think department-purchased design tools, free-tier analytics platforms, or AI products signed up with a work email. These create security blind spots: access is granted informally, there is no offboarding process, and sensitive data can end up in systems nobody is tracking. Adding these as manual applications in Ravenna brings them under governance immediately, giving you request workflows, approval routing, and a clear record of who has access.
Where Ravenna fits in your identity stack
Most organizations already use an identity provider like Okta, Google Workspace, or Microsoft Entra ID to manage authentication and baseline access. Ravenna is not a replacement for your IdP. Instead, it adds the governance, approval, and request layer that identity providers do not provide natively.Your identity provider handles birthright access: the baseline permissions every employee gets automatically based on their role, department, or location. These are managed through IdP group rules that apply access as employee attributes change.Ravenna handles just-in-time access: the ad hoc or incremental requests that fall outside standard birthright grants. These are project-based needs, temporary responsibilities, or exceptions that require human decision-making, approval workflows, and audit trails.For the joiner phase of the employee lifecycle, Ravenna complements your IdP by triggering onboarding workflows when a new employee is detected. These workflows can send forms to hiring managers, provision access to applications not covered by SSO, add users to Slack channels, and create tickets for manual provisioning steps.For movers and leavers, Ravenna’s entitlement tracking gives you a clear record of who has access to what. Time-bound entitlements expire automatically, and revocation of synced-app access triggers deprovisioning in the IdP immediately.
Enabling for agents
Toggle Software Access Requests on in your agent’s Identity tab under Advanced Settings to let it assist with access provisioning. The agent can then show users which applications they are eligible for, surface current access and expiration dates, prefill request forms, and offer to submit renewal requests for expiring grants.The agent respects the same eligibility rules and policies as the form-based flow.Learn more about software access requests for agents
Getting started
1
Import or create applications
Sync your catalog from your identity provider, or add applications manually for tools outside your IdP.
2
Create approval templates
Define who approves access and in what order at Settings > Approval Templates. Policies reference these, so build them first.
3
Create access policies
Set eligibility, allowed durations, and justification requirements, then attach the approval template that should route requests.
4
Define access levels
Set up permission tiers for each application, attach an access policy to each, and choose a provisioning method.
5
Build the request form
Create one form with application and access level select fields. Eligibility filtering tailors it to each requester automatically.
6
Enable agent-assisted requests
Turn on Software Access Requests in your agent’s Identity tab under Advanced Settings so users can request access through Slack.
Follow the full setting up access provisioning guide for step-by-step instructions