Requesting access
Entitlements and business roles can be requested in Nova through an access request. Each requested role is decided by the approval workflow assigned to it. Only after that decision does Nova grant the access.
Who can request what for whom
- Requester: every signed-in identity can submit a request – for itself, for another identity or for a department. Whether access is granted is up to the approvers.
- Requestable are entitlements and business roles that have an “Approval workflow” assigned. Nova does not accept roles without a workflow in any request.
- Several roles: a request can contain several roles. Each runs through its own approval workflow.
- AI agents: access for an AI agent can only be requested by its accountable owner, the owner's registered deputy or administrators. Through requests, an AI agent receives AI capabilities (roles
nova-ai:*) only; these cannot be requested for any other identity.
Submitting a request
Under “Access requests” → “My requests”, “New request” opens the form:
- “Requested for” – a person or a department. The signed-in identity is preselected.
- “Roles” – the requestable entitlements and business roles, searchable and filterable by “Category”. Roles that all target identities already hold are hidden.
- Pre-check – Nova checks the selection against the segregation of duties rules and shows conflicts as “Risk findings”. Depending on the risk policy, Nova only warns, adds a review step or blocks the request.
- “Submit request”.
For a department, Nova creates one shared request: approvers decide once for the whole department, not per person. Which people receive the access is determined only at final approval, from the members at that time.
An access request carries no validity dates. An assignment resulting from it is valid from the approval onwards, without an end date.
Request status
| Status | Meaning |
|---|---|
| “Pending” | At least one requested role has not been decided yet. |
| “Approved” | All requested roles are approved. |
| “Partially approved” | All roles are decided – some approved, some rejected. |
| “Rejected” | All requested roles are rejected. |
| “Cancelled” | The request was withdrawn or cancelled by an administrator. |
The “Access requests” page has three tabs: “To approve” shows what the signed-in identity may decide – including as a deputy –, “My requests” its own open requests and “Completed” the finished ones. Administrators see all requests under “To approve” and “Completed”. Each request has a chat between requester and approvers; Nova records decisions there as system messages.
After the decision
As soon as every role in a request has been decided, Nova assigns the approved roles to the target identities. Existing assignments stay unchanged. Rejected and cancelled requests lead to no assignment.
If “Auto-provision backend systems” is switched on under “Administration” → “Provisioning” → “Mapping”, Nova also creates a provisioning run for each identity whose new roles affect a target system:
- Nova saves the assignment and the run in the same transaction. If saving fails, neither is created.
- Nova starts the run only afterwards. If the run cannot be started, it stays saved and Nova resumes it at its next start.
If the option is switched off, Nova assigns the roles in Nova only. In the request, the “Provisioning” section shows the state of the runs. “Approved” means: assigned in Nova. Nova tracks the execution in the target systems separately.
Withdrawing and cancelling
While a request is “Pending”, the requester can withdraw it with “Cancel request”. Administrators can cancel any open request. A cancelled request cannot be reopened. Nova notifies the approvers of open steps and logs the cancellation.