Skip to main content
Access provisioning handles the full lifecycle of application access in your organization: users request access, policies determine eligibility and route approvals, and identity provider integrations grant access automatically once approved. Every request is tracked as an entitlement with clear status, expiration, and audit trail.

What you can do

Import and manage applications

Sync your application catalog from Okta, Google Workspace, or Entra ID. Define access levels with provisioning methods that map to IdP groups for automated granting.

Define access policies

Control who can request access, link approval templates, set duration options, and require business justification. Policies sit between users and access levels.

Track entitlements

Every approved request becomes an entitlement. Monitor active grants, handle extensions and revocations, and respond to provisioning failures.

Enable agent-assisted requests

Let your AI agent help users discover eligible applications, submit requests, and renew expiring access through conversation in Slack.

How it works

A user requests access to an application, either by submitting a form or asking the AI agent. Ravenna evaluates the access policy to confirm the user is eligible, then applies the linked approval template to route the request to the right approvers. Once approved, access is provisioned through your identity provider automatically.For applications without an identity provider connection, provisioning is manual: an authorized person grants access in the target system and confirms it in Ravenna.

Key concepts

Applications

are the tools and services your organization manages access to. They can be synced from your identity provider (Okta, Google Workspace, Microsoft Entra ID) or created manually for tools outside your IdP.Each application has one or more access levels representing permission tiers, like Viewer, Editor, or Admin. Each access level specifies a provisioning method:Group and Application give you end-to-end automation with no workflow to build. Reach for Workflow only when provisioning needs custom logic the other methods cannot express.

Access policies

govern who can request each access level and under what conditions. A policy defines:
  • Eligibility based on user group membership
  • Approval template for routing requests to the right approvers
  • Duration options for how long access should last
  • Business justification requirements
When no policy is attached to an access level, requests are auto-approved. Attach a policy to add governance without changing the provisioning path.
Learn more about access policies

Entitlements

An is a concrete access grant: a record that a specific user has been provisioned a specific access level on a specific application. Entitlements track status (provisioned, deprovisioned, failed), expiration dates, and the full history of how access was granted.
Learn more about entitlements

Synced vs manual applications

Synced applications import from your identity provider. Their access levels map to IdP groups, so after approval Ravenna adds the user to the correct group and access flows through your existing assignment rules. Changes in the IdP sync back to Ravenna automatically.Manual applications are for tools not managed by an IdP. After approval, an authorized provisioner (the application owner, ticket assignee, or a workspace admin) grants access in the target system and confirms it in Ravenna. This is particularly valuable for bringing untracked tools under governance: teams often adopt SaaS products outside of IT’s visibility, and manual applications give you a formal request flow and audit trail for these tools without requiring an IdP connection.
What is Shadow IT? Shadow IT refers to tools and services adopted by teams without IT’s knowledge or approval. Think department-purchased design tools, free-tier analytics platforms, or AI products signed up with a work email. These create security blind spots: access is granted informally, there is no offboarding process, and sensitive data can end up in systems nobody is tracking. Adding these as manual applications in Ravenna brings them under governance immediately, giving you request workflows, approval routing, and a clear record of who has access.
Most organizations use a mix of both synced and manual applications. Start with synced applications for automated provisioning, then add manual entries for anything outside your IdP.

Where Ravenna fits in your identity stack

Most organizations already use an identity provider like Okta, Google Workspace, or Microsoft Entra ID to manage authentication and baseline access. Ravenna is not a replacement for your IdP. Instead, it adds the governance, approval, and request layer that identity providers do not provide natively.Your identity provider handles birthright access: the baseline permissions every employee gets automatically based on their role, department, or location. These are managed through IdP group rules that apply access as employee attributes change.Ravenna handles just-in-time access: the ad hoc or incremental requests that fall outside standard birthright grants. These are project-based needs, temporary responsibilities, or exceptions that require human decision-making, approval workflows, and audit trails.For the joiner phase of the employee lifecycle, Ravenna complements your IdP by triggering onboarding workflows when a new employee is detected. These workflows can send forms to hiring managers, provision access to applications not covered by SSO, add users to Slack channels, and create tickets for manual provisioning steps.For movers and leavers, Ravenna’s entitlement tracking gives you a clear record of who has access to what. Time-bound entitlements expire automatically, and revocation of synced-app access triggers deprovisioning in the IdP immediately.

Enabling for agents

Toggle Software Access Requests on in your agent’s Identity tab under Advanced Settings to let it assist with access provisioning. The agent can then show users which applications they are eligible for, surface current access and expiration dates, prefill request forms, and offer to submit renewal requests for expiring grants.The agent respects the same eligibility rules and policies as the form-based flow.

Getting started

1

Import or create applications

Sync your catalog from your identity provider, or add applications manually for tools outside your IdP.
2

Create approval templates

Define who approves access and in what order at Settings > Approval Templates. Policies reference these, so build them first.
3

Create access policies

Set eligibility, allowed durations, and justification requirements, then attach the approval template that should route requests.
4

Define access levels

Set up permission tiers for each application, attach an access policy to each, and choose a provisioning method.
5

Build the request form

Create one form with application and access level select fields. Eligibility filtering tailors it to each requester automatically.
6

Enable agent-assisted requests

Turn on Software Access Requests in your agent’s Identity tab under Advanced Settings so users can request access through Slack.
Follow the full setting up access provisioning guide for step-by-step instructions
Last modified on August 5, 2026