<!--
Generated from a Ledgerium SOP template.
Fill in the [bracketed] fields for your process, or delete this block before publishing.
-->

# System access request SOP template

## How to use this template

- Fields written as `[fill in: ...]` are blanks — replace each one with the value for your process.
- Lines starting with `>` are guidance, not part of the SOP — delete them once you've filled in the real content.
- Recording this process in Ledgerium generates a filled-in version of this SOP automatically.

## Document control

- Process owner: [fill in: process owner]
- Version: [fill in: version]
- Effective date: [fill in: effective date]
- Last reviewed: [fill in: last reviewed date]
- Approved by: [fill in: approver name or title]

## Applies to / Use when

> Who uses it: Employees requesting access, the manager and system owner who approve, and the IT team that provisions. The security lead owns the access policy and auditors reference it for access controls.
> When to use it: Use it when onboarding IT staff, standardizing how access is requested and approved across systems, or documenting an access control for a security audit.

- Applies to: [fill in: who this applies to in your organization]
- Use when: [fill in: when your team should follow this procedure]

## Purpose

> Why the procedure exists and the least-privilege and access control it enforces.

[fill in: purpose details]

## Scope

> Which systems and access levels the procedure covers, and what is out of scope.

[fill in: scope details]

## Roles

> Who requests, who approves as manager and system owner, and who provisions.

[fill in: roles details]

## Procedure

> The ordered steps from request to confirmed, least-privilege access.

[fill in: procedure details]

## Exceptions

> How to handle privileged access, temporary access, and denied requests.

[fill in: exceptions details]

## Records

> What approval evidence is kept and where access grants are logged, for audit.

[fill in: records details]

## Worked example — steps from a real recording

> Example steps from a real recording — replace with your own.

1. **Submit the request** — Enter the system, role, and business reason for access.
2. **Approve the request** — Manager and system owner approve the access level.
3. **Apply least privilege** — Confirm the grant is limited to what the role requires.
4. **Provision the access** — Create or update the account in the identity system.
5. **Confirm and log** — Verify the user has access and log the grant for review.
6. [fill in: step]
7. [fill in: step]

## Review checklist — common mistakes to avoid

- [ ] Leaving the system-owner approval out, so access is granted without review
- [ ] Granting broad access instead of only what the role needs
- [ ] Not logging the grant, so there is no audit trail of who has access

## Limitations of this template

A template is a starting structure. Your real approval routing and least-privilege rules are captured best by recording an actual access request rather than filling in a blank outline.

---
Template: https://ledgerium.ai/sop-templates/system-access-request · Generated automatically from a real recording, or fill in by hand.

Template last updated: July 2026
From Ledgerium recordings: A generated access request SOP captures the system-owner approval and the least-privilege grant step by step and times the provisioning wait, so it shows where access requests stall, which a happy-path template never captures.
See the full recorded workflow: https://ledgerium.ai/workflow-library/access-provisioning-workflow
