User Privilege Request & Approval Process
This SOP defines the standardized process for requesting, reviewing, approving, and assigning elevated privileges through Sentinel Privilege Manager (SPM).
1. Purpose & Scope
The purpose of this SOP is to establish a consistent and auditable process for managing user requests for elevated application or endpoint privileges.
The procedure applies to employees, contractors, service desk personnel, application owners, and security administrators involved in privilege requests.
2. Roles & Responsibilities
| Role | Responsibility |
|---|---|
| Requester | Provides the business justification, requested application, duration, and required privilege level. |
| Manager | Reviews the business requirement and confirms that the request is justified. |
| Application Owner | Validates application-specific requirements where applicable. |
| Security Administrator | Validates policy compliance and assigns the approved privilege. |
| Service Desk | Tracks requests and assists users with submission or status-related queries. |
3. Inputs & Prerequisites
The following information must be available before a privilege request is submitted.
- Valid SPM user account.
- Application or resource requiring elevated access.
- Business justification for the request.
- Required privilege level.
- Requested access duration.
- Manager or designated approver information.
4. Process Overview
The privilege request lifecycle follows a controlled approval flow.
Each stage must be completed before the request proceeds to the next stage.
5. Procedure
Submit the Request
The requester signs in to SPM and opens a new privilege request.
- Select the required endpoint or application.
- Select the required privilege level.
- Enter the business justification.
- Specify the requested access duration.
- Select the applicable approver.
- Submit the request.
Validate the Request
The request is reviewed for completeness and consistency with the stated business requirement.
- Confirm that the requester is authorized.
- Verify the target application or endpoint.
- Review the requested privilege level.
- Check the requested access duration.
Review and Approve
The designated approver reviews the request and either approves or rejects it based on the documented business requirement.
| Decision | Action |
|---|---|
| Approve | Request proceeds to privilege assignment. |
| Reject | Request is closed with the rejection reason recorded. |
| Return | Requester provides missing or corrected information. |
Assign the Privilege
After approval, the security administrator assigns the approved privilege through SPM.
- Open the approved request.
- Verify the approval status.
- Confirm the target endpoint or application.
- Apply the approved privilege policy.
- Set the approved access duration.
- Save the configuration.
Confirm Completion
The requester receives confirmation that the approved privilege has been assigned.
The administrator records the completion status and verifies that the request contains the required audit information.
6. Approval Rules
Approval requirements may vary according to the privilege level and resource being accessed.
| Request Type | Minimum Approval | Typical Duration |
|---|---|---|
| Standard Application Access | Manager | Business-defined |
| Elevated Application Privilege | Manager + Application Owner | Time-bound |
| Administrative Privilege | Manager + Security Administrator | Strictly time-bound |
7. Exception Handling
Exceptions should be handled through an approved process rather than bypassing the standard workflow.
| Scenario | Required Action |
|---|---|
| Incomplete request | Return the request to the requester for additional information. |
| Incorrect approver | Reassign the request to the designated approval authority. |
| Urgent business requirement | Follow the organization's documented emergency-access process. |
| Privilege no longer required | Initiate privilege removal and update the request record. |
8. Process Controls
The following controls help maintain consistency, accountability, and traceability throughout the process.
- Privileges must be assigned only after the required approval is recorded.
- Business justification must be captured for every elevated-access request.
- Time-bound access should have a defined expiration where applicable.
- Approval and assignment activities must remain traceable to the request.
- Access that is no longer required should be removed according to the organization's access-review process.
9. Records & Audit
The following information should be retained as part of the privilege request record:
- Requester identity.
- Requested application or endpoint.
- Business justification.
- Requested privilege level.
- Approval decision and approver.
- Privilege assignment details.
- Request and completion timestamps.
- Access expiration, where applicable.
10. Completion Criteria
The procedure is considered complete when all applicable conditions below have been satisfied:
- Request contains the required information.
- Required approvals have been recorded.
- Approved privilege has been assigned.
- Requester has been notified.
- Request status has been updated.
- Audit information has been retained.
11. Document Information
| Document Owner | Security Operations |
|---|---|
| Document Type | Standard Operating Procedure |
| Version | 1.0 |
| Review Frequency | Periodic / As required |
| Status | Sample |