Access Requests
Self-service access to SharePoint sites, distribution lists, shared mailboxes, and any resource your admins define - with approval routing, fulfillment guidance, and a complete audit trail. Last updated 2026-07-14
What it is
Access Requests give end users a structured way to ask for access to a resource - instead of an ad-hoc email or chat. Each request is filed against a request type (SharePoint Site Access, Distribution List Membership, Shared Mailbox Access, or a custom type your organization defines), routed to the right approver, and tracked from submission through fulfillment. Nothing is granted automatically: every request is a documented, auditable decision.
The feature spans three surfaces:
- My TATER (
my.tatersecurity.com) - where users browse the catalog and submit requests. - TATER Security (
app.tatersecurity.com) - where admins define request types and review the audit log. - My Approvals - where approvers see pending requests alongside every other TATER approval.
Submitting a request (end users)
- Open My TATER and go to Requests → New request.
- Pick a request type from the catalog. Each card shows an icon, a category (Collaboration, Email, …), and a short description of what it grants.
- Fill in the resource - e.g. the SharePoint site URL, the distribution list address, or the shared mailbox - and any type-specific fields (for example, an Access level of Read / Contribute / Full Control).
- Add a justification / business reason. Approvers rely on this, so be specific.
- Submit. The request enters Pending status and is routed to its approver.
You can watch progress under Requests → My requests, and cancel a request that's still Pending if you no longer need it.
Built-in request types
Every organization starts with three ready-to-use starter types (an admin clicks Seed starter types once to create them):
| Type | Category | Collects | Fulfillment |
|---|---|---|---|
| SharePoint Site Access | Collaboration | Site URL + access level (Read / Contribute / Full Control) | Guidance + Ops task; default duration 365 days |
| Distribution List Membership | Distribution list / M365 group address | Guidance + Ops task | |
| Shared Mailbox Access | Shared mailbox + permission (Full Access / Send As / Send on Behalf) | Guidance + Ops task |
Approval routing
Each request type carries an approver mode that decides who signs off:
- Org admins (default) - any Admin / OrgAdmin in the organization can approve.
- Group - members of a designated approver group. Use this to delegate, e.g. a data-owner group for a sensitive SharePoint site.
Requests flow through TATER's universal approval engine, so they appear in the approver's My Approvals queue next to change requests, expenses, and every other approval - and generate the same branded email notification, reminders, and escalation. The approver can Approve or Deny (with a reason). Statuses:
| Status | Meaning |
|---|---|
| Pending | Awaiting an approval decision. |
| Approved | Decision made; ready to be fulfilled (access granted). |
| Denied | Approver rejected the request, with a reason. |
| Fulfilled | Access has been granted and the request closed out. |
| Cancelled | Withdrawn by the requester before a decision. |
| Expired | A time-boxed grant reached the end of its duration. |
Fulfillment
Approval records the decision; fulfillment is the action. When a request type has Create Ops task enabled, approving the request opens a task in TATER Ops (category Access Request) for the fulfilling team, carrying the request's guidance text - step-by-step instructions for granting the access in the SharePoint, Exchange, or Entra admin center. Once the access is granted, mark the request Fulfilled to close the loop. Types with a default duration record when a time-boxed grant should be reviewed or revoked.
Defining custom request types (admins)
Admins manage request types in TATER Security → Access Requests. Create a type with:
- Name, category, icon, description - what shows on the catalog card.
- Resource label + placeholder - what the user names (a site, a mailbox, an app, a role).
- Custom fields - typed inputs (text, select with options, …) marked required or optional, e.g. an access level or environment.
- Approver mode - org admins or a specific approver group.
- Fulfillment - guidance text for the fulfilling team, and whether to auto-create an Ops task on approval.
- Default duration - for access that should be time-boxed and re-reviewed.
Because the catalog is API-driven, a new type appears in every user's My TATER request catalog immediately - no deployment needed.
Audit trail
Every action - submission, approval, denial, cancellation, fulfillment - is written to the Activity Log with the actor, timestamp, and channel (via). Requests submitted or approved by an AI assistant on a user's behalf are recorded the same way, so there's always a complete, exportable record of who asked for what and who granted it. This log feeds the Access Review (UAR) report in TATER Insights.
Requesting via AI assistants
MCP-enabled assistants (Microsoft 365 Copilot, Claude, and others) can drive the whole flow, always audit-tracked:
list_access_request_types- browse the catalog of available request types.submit_access_request- file a request on the user's behalf (resource + fields + justification).list_access_requests- check the status of open or past requests.
See Using AI Assistants with TATER for how MCP access works.
Related guides
- My TATER (where you submit requests)
- TATER Ops (where fulfillment tasks land)
- TATER Insights - Access Review (UAR) report
- Activity Log & the
viachannel field
Was this page helpful?
TATER