Security owner
The action waits until this owner approves or denies it.
Workflows · Privileged-access grants
Keep the requesting agent, recipient, role, duration, decision, and directory result together.
Agent request
The role permits changes to production systems during the grant window.
Policy decision
The action waits until this owner approves or denies it.
The identity provider applies the approved role and returns the grant result.
The recipient keeps current access and the role is not granted.
Execution order
The request, decision, recorded cost, and execution result remain in activity history.