For Roles, you patch the Role’s accessRequestConfig:
For Entitlements, you put entitlement request config:
The nightmare-ish upper/lower case, with/without underscore, workgroup vs GOVERANCE_GROUP…what is going on?
Is there a standardised approach to this, or was this all developed by different teams?
And separately, what’s with the different cmdlet naming convention:

This kind of interfacing is rather ugly, IMO.

