Skip to content
IT operationsBuilt app template

Access request management template

An access request management app for IT teams managing temporary application access. Check requested roles and duration against application policy, collect manager, owner and conditional security reviews, and track manual provisioning, periodic access review and revocation evidence.

»Built by ToolJet·Reviewed ·Change the design, branding, and features with AI
Access desk · Dashboard screenshot
Access desk with a review and fulfillment queue, access assurance panel and application access coverage.
Actual app · Sample data
AT A GLANCE

What is this access requests template?

Access desk connects request intake, review decisions and access assurance in one workspace. Applications define allowed roles, maximum access duration and a security reviewer. Restricted or privileged requests add a security responsibility. Decisions apply to a specific scope revision; revising the role, dates, class or justification requests fresh decisions while retaining earlier evidence. Staff record provisioning checks after working in the source system and can periodically confirm continued need or request revocation. The English desktop pilot includes fictional ToolJet Database data. Public download and deployment await export and clean-install validation.

Screens
4 connected pages
Data source
ToolJet Database
Language
English
Access changes
Recorded manually

Built for IT service teams coordinating employee application access with managers and application owners.

THE WORKFLOW

From requested scope to ongoing access assurance.

Keep application policy, current review decisions and the external access handoff connected.

  1. Review desk

    Find the next decision or handoff

    Open pending reviews and fulfillment handoffs. See grants needing periodic review or removal alongside application coverage.

  2. Requests

    Capture a specific access need

    Create a request with a role, business justification, start and end dates, and standard or privileged class. Filter by stage, class and review attention.

  3. Request workspace

    Record reviews and access evidence

    Record current-scope reviews, approve or reject, verify manual provisioning checks, revise scope, cancel pending work and record periodic access reviews or removal.

  4. Applications

    Maintain ownership and intake

    Maintain owners, sensitivity, security reviewers, allowed roles and maximum access duration. Pause intake when an application should not accept requests.

INSIDE THE TEMPLATE

What does the template cover?

Policy-aware access intake

Requested roles and access duration must satisfy the current application policy. Restricted or privileged access adds Security to the manager and application-owner responsibilities.

Scope revisions and fresh approvals

Approval checks that every required responsibility has approved the current scope revision. Revising scope resets decisions and archives the previous scope and review evidence. Legacy requests require scope confirmation before new approval.

Manual fulfillment with MFA checks

Manual provisioning records an operator, source-system evidence and confirmation that role and expiry match the approval. Restricted or privileged access additionally requires recorded MFA verification. Activation before the start date is blocked.

Periodic access review and revocation handoffs

Periodic access reviews record continued need or a revocation handoff. Expired access cannot be retained. Operators record removal evidence after completing the action in the source system; cancelling an unprovisioned request retains its history.

ToolJet Database with sample data

The pilot uses 2 tables with fictional records. No external database is needed to explore the source app.

Data included in the access requests pilot
TableSample dataWhat it stores
Applications6 sample applicationsApplication owners, sensitivity, intake availability and optional role, duration and security-review policies.
Access requests13 sample requestsEmployee requests across review, approved, active and revocation stages, with scope revisions, assigned decisions and access assurance evidence.
Where this template stops

No identity-provider integration, automated provisioning, automatic account expiry, notifications or file uploads are included. Reviewers and operators are manually recorded; identity, independent reviewers and server-enforced role authorization are not verified. Policy and revision checks coordinate work in this app and do not secure external systems. Database uniqueness constraints and loaded-data prechecks cover references and application names; case-normalization behavior across concurrent sessions is unverified. The pilot loads up to 1,000 rows per table and blocks writes at that limit. Reopen a selected request after hard reload. Export portability and clean installation remain unverified.

YOUR DESIGN. YOUR BRAND. YOUR WORKFLOW.

Make it yours with AI.

This design is a starting point. Describe the look you want, add your logo and brand colors, or ask for new features in a prompt. Use the starter prompt to build your own version in the ToolJet AI builder, or use a suggested prompt to modify an app you already have. Review and test the result.

Start with an idea
Edit this prompt before copying.

Suggested prompts describe changes you can request. Additional features and translations still need to be built and tested.

FROM TEMPLATE TO YOUR TOOL

How to use this template.

  1. Add it to your workspace

    Choose ToolJet Cloud, or download the application package to import into your self-hosted instance once the template is released.

  2. Start with the included database

    Explore the sample records in ToolJet Database, then add your records and configure the workflow for your team.

  3. Make it work your way

    Describe your preferred design, branding, and new features in the AI builder. Test your workflow, then share your app with the people who need it.

A FEW THINGS TO KNOW

Template FAQs

What does this access request template include?

It includes policy-aware intake, scope revisions, manager and owner reviews, conditional Security review, approval decisions, manual fulfillment checks, periodic access reviews and revocation evidence.

Does it grant or revoke access automatically?

No. Staff change access in the source system and record the operator and evidence here. Review dates and access end dates highlight work; they do not run external account changes.

When is Security review required?

Restricted applications and requests marked privileged require an additional Security decision. The application policy provides the assigned security reviewer.

What happens when the requested scope changes?

Revising an unprovisioned request archives the prior scope and decisions, increments the scope revision and resets assigned decisions. Approval requires reviews for the current revision.

Can the app review existing active access?

Yes. Record continued need and the next review date, or request revocation. Expired grants cannot be retained, and removal still requires a separate operator evidence record.

Does it enforce reviewer identity or segregation of duties?

No. The app records names and responsibilities manually. Enforced identity, role permissions and separation of duties need additional implementation and testing.

Can I customize the design and workflow with AI?

Use the starter prompt or follow-up prompts to change branding, layout, fields and workflow. Integrations, language support and authorization controls require implementation and testing.

Is it ready to deploy or download?

The local pilot uses fictional ToolJet Database data. Public deployment and download remain disabled until export and clean installation are validated.

TEMPLATE DESIGN PREVIEW

Access request management

Actual dashboard screenshots from the built pilot, with fictional sample data.

App appearance
Access desk with a review and fulfillment queue, access assurance panel and application access coverage.