IT access request process flowchart
A worked example to adapt. Rename steps, add branches and owners to match how your team actually works.
Mermaid source for this diagram
flowchart TD
s(["Employee requests access"])
mgr{"Manager approves?"}
deny(["Request denied with reason"])
d2{"Privileged or sensitive system?"}
own{"System owner approves?"}
prov["IT provisions access"]
note["Notify requester"]
log["Log in access register"]
e(["Include in periodic access review"])
s --> mgr
mgr -->|No| deny
mgr -->|Yes| d2
d2 -->|Yes| own
d2 -->|No| prov
own -->|Yes| prov
own -->|No| deny
prov --> note
note --> log
log --> ePaste into any Markdown tool that renders Mermaid, such as GitHub.
About this it access request process flowchart
Access requests are a basic security control: people get the access their role needs, with approvals on record. This flowchart adds a second approval for privileged or sensitive systems and ends with the access register used for periodic reviews.
It fits help desks and IT teams working toward least-privilege access.
Step by step
- Request. The employee names the system and the reason.
- Manager approval. The manager confirms the access fits the role.
- Owner approval. Privileged or sensitive systems also need the system owner's approval.
- Provision. IT grants access and notifies the requester.
- Record. The grant is logged for periodic access reviews.
How to make it in flow-chart.io
- Start from the example. Edit the text in the generator box above so it names your own systems and approval rules, then press Generate. The free preview needs no sign-up.
- Add the branches. Add the decision points that matter for you, for example temporary access? or production database?. Each decision becomes a diamond with labeled outcomes.
- Assign owners. Save the diagram to the editor (free account) and rename steps to show who does what: requester, manager, system owner and IT.
- Share or export. Share a read-only view link: people with the link can view the diagram but not edit it. Downloads as PNG, SVG or PDF are part of Flow Pro (see pricing).
Tips
- Set an expiry on temporary access.
- Keep approvals with the ticket for audit.
- Review privileged access more often than standard access.
Frequently asked questions
- What is least privilege?
- Giving each person only the access needed for their job.
- Why log access grants?
- A register makes periodic access reviews and audits possible.
- Can I generate a version for my systems?
- Yes. Edit the steps in the generator box and press Generate.