tatersecurity.com Open App

Access Requests

Self-service access to SharePoint sites, distribution lists, shared mailboxes, and any resource your admins define - with approval routing, fulfillment guidance, and a complete audit trail. Last updated 2026-07-14

What it is

Access Requests give end users a structured way to ask for access to a resource - instead of an ad-hoc email or chat. Each request is filed against a request type (SharePoint Site Access, Distribution List Membership, Shared Mailbox Access, or a custom type your organization defines), routed to the right approver, and tracked from submission through fulfillment. Nothing is granted automatically: every request is a documented, auditable decision.

The feature spans three surfaces:

  • My TATER (my.tatersecurity.com) - where users browse the catalog and submit requests.
  • TATER Security (app.tatersecurity.com) - where admins define request types and review the audit log.
  • My Approvals - where approvers see pending requests alongside every other TATER approval.

Submitting a request (end users)

  1. Open My TATER and go to Requests → New request.
  2. Pick a request type from the catalog. Each card shows an icon, a category (Collaboration, Email, …), and a short description of what it grants.
  3. Fill in the resource - e.g. the SharePoint site URL, the distribution list address, or the shared mailbox - and any type-specific fields (for example, an Access level of Read / Contribute / Full Control).
  4. Add a justification / business reason. Approvers rely on this, so be specific.
  5. Submit. The request enters Pending status and is routed to its approver.

You can watch progress under Requests → My requests, and cancel a request that's still Pending if you no longer need it.

Built-in request types

Every organization starts with three ready-to-use starter types (an admin clicks Seed starter types once to create them):

TypeCategoryCollectsFulfillment
SharePoint Site AccessCollaborationSite URL + access level (Read / Contribute / Full Control)Guidance + Ops task; default duration 365 days
Distribution List MembershipEmailDistribution list / M365 group addressGuidance + Ops task
Shared Mailbox AccessEmailShared mailbox + permission (Full Access / Send As / Send on Behalf)Guidance + Ops task

Approval routing

Each request type carries an approver mode that decides who signs off:

  • Org admins (default) - any Admin / OrgAdmin in the organization can approve.
  • Group - members of a designated approver group. Use this to delegate, e.g. a data-owner group for a sensitive SharePoint site.

Requests flow through TATER's universal approval engine, so they appear in the approver's My Approvals queue next to change requests, expenses, and every other approval - and generate the same branded email notification, reminders, and escalation. The approver can Approve or Deny (with a reason). Statuses:

StatusMeaning
PendingAwaiting an approval decision.
ApprovedDecision made; ready to be fulfilled (access granted).
DeniedApprover rejected the request, with a reason.
FulfilledAccess has been granted and the request closed out.
CancelledWithdrawn by the requester before a decision.
ExpiredA time-boxed grant reached the end of its duration.

Fulfillment

Approval records the decision; fulfillment is the action. When a request type has Create Ops task enabled, approving the request opens a task in TATER Ops (category Access Request) for the fulfilling team, carrying the request's guidance text - step-by-step instructions for granting the access in the SharePoint, Exchange, or Entra admin center. Once the access is granted, mark the request Fulfilled to close the loop. Types with a default duration record when a time-boxed grant should be reviewed or revoked.

Defining custom request types (admins)

Admins manage request types in TATER Security → Access Requests. Create a type with:

  • Name, category, icon, description - what shows on the catalog card.
  • Resource label + placeholder - what the user names (a site, a mailbox, an app, a role).
  • Custom fields - typed inputs (text, select with options, …) marked required or optional, e.g. an access level or environment.
  • Approver mode - org admins or a specific approver group.
  • Fulfillment - guidance text for the fulfilling team, and whether to auto-create an Ops task on approval.
  • Default duration - for access that should be time-boxed and re-reviewed.

Because the catalog is API-driven, a new type appears in every user's My TATER request catalog immediately - no deployment needed.

Audit trail

Every action - submission, approval, denial, cancellation, fulfillment - is written to the Activity Log with the actor, timestamp, and channel (via). Requests submitted or approved by an AI assistant on a user's behalf are recorded the same way, so there's always a complete, exportable record of who asked for what and who granted it. This log feeds the Access Review (UAR) report in TATER Insights.

Requesting via AI assistants

MCP-enabled assistants (Microsoft 365 Copilot, Claude, and others) can drive the whole flow, always audit-tracked:

  • list_access_request_types - browse the catalog of available request types.
  • submit_access_request - file a request on the user's behalf (resource + fields + justification).
  • list_access_requests - check the status of open or past requests.

See Using AI Assistants with TATER for how MCP access works.

Was this page helpful?