Forms for Access Request allows you to define custom forms and attach them directly to specific access items, including Roles, Access Profiles, and Entitlements. When a user requests an item with an attached form, they will be prompted to provide the required supplementary data before submitting their request.
Problem
Determining who gets access to what—and how that access should be configured—often requires more than a simple “approve” or “deny.” Customers frequently need to collect specific, contextual information at the time of the request to make informed approval decisions and execute complex provisioning tasks.
Solution
Identity Security Cloud (ISC) Admins can now define custom forms and attach them directly to specific access items, including Roles, Access Profiles, and Entitlements. When a user requests an item with an attached form, they will be prompted to provide the required supplementary data before submitting their request.
Key Benefits & Capabilities
Context-Driven Approvals: Form data is passed directly to approvers as name-value pairs, giving them the exact context they need to make confident, secure approval decisions.
Smarter Provisioning: Submitted form data doesn’t just stop at the approval stage; it is accessible throughout the request flow. Admins can programmatically access this data to drive custom provisioning logic (such as before-provisioning rules).
Seamless User Experience: If a form is required for multiple requested items, form data is automatically copied to each form instance. Requesters also have the ability to revisit and edit their forms in the Request Center prior to final submission.
Third-Party Integration Support: If you use an external UI for your access request portal (such as the SailPoint ServiceNow Catalog Integration), you can securely pass this supplementary data into the request flow independent of the native UI.
Also is there any additional documentation on how to configure or where to set this up. Apologies, this has been a feature we need that solves many of our request from apps so very excited to hear that it’s available.
@PGookin , Awesome feature! Is there an option to block access request submission based on a form input? For example, the request should only be allowed if Training Completed is set to Yes. If it’s set to No, the access request submission should be blocked.
Hi @PGookin, great feature. You mentioned that the form inputs should show up on the provisioning plan, can you specify where in the plan we should see them? Is it in the plan arguments? Would like to seriously consider this for a few use cases, so some documentation around the whole feature would be awesome. Please link it here when available! Thanks
@PGookin I can’t see this feature yet in our sandbox tenant under Access Profile → Access Request. Could you please let me know how to attach a form to an Access Profile? Am I missing any configuration or prerequisite?
Hi Aditya, to attach a form to an access profile, edit the access profile and select Access Request from the left hand menu. Toggle the “Enable Access Request Form” option to On and then select the form you want. Here’s a screenshot:
Hi Sagar, when you edit a role, access profile, or entitlement you should see a new configuration option “Require Access Request Form” which allows you to add a form to the item. If you don’t see this, your staging tenant may not be enabled yet. Let me know if this is the case and I can look into it.
Awesome feature, can’t wait to try few intresting IIQ customisations here ,
Quick question: from above thread looks like form values can be either drop down or auto populated with help of plan object was also possible to input additional key,values to access request with help of this custom form
Instead of access object level can we add form at application like IIQ ?