STANDARD OPERATING PROCEDURE

User Privilege Request & Approval Process

This SOP defines the standardized process for requesting, reviewing, approving, and assigning elevated privileges through Sentinel Privilege Manager (SPM).

1. Purpose & Scope

The purpose of this SOP is to establish a consistent and auditable process for managing user requests for elevated application or endpoint privileges.

The procedure applies to employees, contractors, service desk personnel, application owners, and security administrators involved in privilege requests.

What this SOP covers: Request submission, request validation, approval, privilege assignment, notification, and record retention.

2. Roles & Responsibilities

Role Responsibility
Requester Provides the business justification, requested application, duration, and required privilege level.
Manager Reviews the business requirement and confirms that the request is justified.
Application Owner Validates application-specific requirements where applicable.
Security Administrator Validates policy compliance and assigns the approved privilege.
Service Desk Tracks requests and assists users with submission or status-related queries.

3. Inputs & Prerequisites

The following information must be available before a privilege request is submitted.

  • Valid SPM user account.
  • Application or resource requiring elevated access.
  • Business justification for the request.
  • Required privilege level.
  • Requested access duration.
  • Manager or designated approver information.
Important: Privilege requests must contain sufficient business justification. Requests with incomplete information may be returned to the requester.

4. Process Overview

The privilege request lifecycle follows a controlled approval flow.

Request
→
Validation
→
Approval
→
Assignment
→
Confirmation

Each stage must be completed before the request proceeds to the next stage.

5. Procedure

1

Submit the Request

The requester signs in to SPM and opens a new privilege request.

  1. Select the required endpoint or application.
  2. Select the required privilege level.
  3. Enter the business justification.
  4. Specify the requested access duration.
  5. Select the applicable approver.
  6. Submit the request.
2

Validate the Request

The request is reviewed for completeness and consistency with the stated business requirement.

  • Confirm that the requester is authorized.
  • Verify the target application or endpoint.
  • Review the requested privilege level.
  • Check the requested access duration.
3

Review and Approve

The designated approver reviews the request and either approves or rejects it based on the documented business requirement.

Decision Action
Approve Request proceeds to privilege assignment.
Reject Request is closed with the rejection reason recorded.
Return Requester provides missing or corrected information.
4

Assign the Privilege

After approval, the security administrator assigns the approved privilege through SPM.

  1. Open the approved request.
  2. Verify the approval status.
  3. Confirm the target endpoint or application.
  4. Apply the approved privilege policy.
  5. Set the approved access duration.
  6. Save the configuration.
5

Confirm Completion

The requester receives confirmation that the approved privilege has been assigned.

The administrator records the completion status and verifies that the request contains the required audit information.

6. Approval Rules

Approval requirements may vary according to the privilege level and resource being accessed.

Request Type Minimum Approval Typical Duration
Standard Application Access Manager Business-defined
Elevated Application Privilege Manager + Application Owner Time-bound
Administrative Privilege Manager + Security Administrator Strictly time-bound
Approval requirements shown in this portfolio sample are illustrative. Organizations should configure approval policies according to their own security and access-control requirements.

7. Exception Handling

Exceptions should be handled through an approved process rather than bypassing the standard workflow.

Scenario Required Action
Incomplete request Return the request to the requester for additional information.
Incorrect approver Reassign the request to the designated approval authority.
Urgent business requirement Follow the organization's documented emergency-access process.
Privilege no longer required Initiate privilege removal and update the request record.

8. Process Controls

The following controls help maintain consistency, accountability, and traceability throughout the process.

  • Privileges must be assigned only after the required approval is recorded.
  • Business justification must be captured for every elevated-access request.
  • Time-bound access should have a defined expiration where applicable.
  • Approval and assignment activities must remain traceable to the request.
  • Access that is no longer required should be removed according to the organization's access-review process.

9. Records & Audit

The following information should be retained as part of the privilege request record:

  • Requester identity.
  • Requested application or endpoint.
  • Business justification.
  • Requested privilege level.
  • Approval decision and approver.
  • Privilege assignment details.
  • Request and completion timestamps.
  • Access expiration, where applicable.
These records provide traceability for access reviews, internal controls, and audit activities.

10. Completion Criteria

The procedure is considered complete when all applicable conditions below have been satisfied:

  • Request contains the required information.
  • Required approvals have been recorded.
  • Approved privilege has been assigned.
  • Requester has been notified.
  • Request status has been updated.
  • Audit information has been retained.

11. Document Information

Document Owner Security Operations
Document Type Standard Operating Procedure
Version 1.0
Review Frequency Periodic / As required
Status Sample
Portfolio Sample: This document is a fictionalized technical-writing sample created for portfolio demonstration purposes. Sentinel Privilege Manager, workflows, roles, configurations, and process details are illustrative and do not represent a real production system.
← Back to Technical Writing Portfolio