IT & Security
Access requests that close the loop
Grant, review and revoke with the approval recorded next to the reason — and an exception that actually expires.
What this usually looks like today
Access is granted in a ticket and never reviewed again.
Vendor security reviews start after the contract is signed.
Exceptions to policy have no expiry and no owner.
Workflows
What it & security teams run in Branchsolve
Each of these is a description away. None of them is a template you have to adopt.
Access requests
System and privilege level decide the approver; production and admin rights escalate.
Vendor security review
Data classification and hosting model routed to security, with legal in parallel when personal data is involved.
Policy exceptions
Compensating control and expiry date required before it can be submitted.
Change advisory board
Risk and blast radius decide whether it is a standard change or needs the full board.
Production deployments
Out-of-window releases require a second approver who is not the requester.
Offboarding checks
A task chain where each system owner records completion.
Routing
Thresholds you can see before you commit
Branchsolve derives the boundary cases from the workflow’s own rules and shows you where each one lands. Nobody types this table out — it falls out of what you described.
Access request
- Read-only, non-productionManager
- Write access, non-productionManager, then System owner
- Any production access…plus Security
- Administrator rights…plus CISO
Questions we get from it & security teams
How does Branchsolve itself handle access?
Three roles, a closed capability matrix, and every action re-checked against live membership on every call. Suspending someone closes their session, their connector token and their notifications at once.
What does the AI connector actually get to do?
It acts as the person who connected it, never as the organisation. A granted scope can only narrow what their role already permits — it can never widen it — and every call re-reads live membership.
Can a link in a notification approve something?
No. Opening a notification shows the request. Deciding requires an explicit action from an authenticated identity, so no preview fetch or link scanner can approve anything.
Your process doesn’t have to be on this list
If you can describe it, Branchsolve can run it. Bring the one that causes the most arguments.
Request a demo