If you are looking for approved and provisioning completed query, please use below:
"Access Request" AND status:complete AND sources:"Active Directory"
Replace source name as per your requirement!
I would also recommend you read below document, which will help you build your query as per the event (find with Access_Request): Audit Events in Cloud Audit - Compass
The result isn’t as expected. Indeed, it doesn’t show that user1 has approved access for user2. It only shows that user2 has now a specific role on the target source. Also, I the “Requestor” and “Recipient” are the same user, which is kind of weird.