Workflows · Privileged-access grants

A two-hour production-admin grant waits on Security.

Keep the requesting agent, recipient, role, duration, decision, and directory result together.

Request a demo

Agent request

Grant production-admin to engineer@example.com for two hours

The role permits changes to production systems during the grant window.

Identity
access-agent · IT operations
Target
engineer@example.com · production-admin
Cost
Recorded agent cost
Evidence
Access request, duration, and ticket reference

Policy decision

Production-admin grants require the Security owner.

Approver

Security owner

The action waits until this owner approves or denies it.

Approved

Tool call resumes

The identity provider applies the approved role and returns the grant result.

Denied

Tool call stays blocked

The recipient keeps current access and the role is not granted.

Execution order

The agent request stops before the connected tool runs.

  1. 01Access agent requests the role grant
  2. 02Deixic checks recipient, role, duration, and policy
  3. 03Security owner decides
  4. 04Connected identity tool returns the grant result

The request, decision, recorded cost, and execution result remain in activity history.

Put this action under policy.

Request a demo.