Skip to content

Self-provisioning

Self-provisioning lets a user activate an entitlement themselves after one manual approval, without asking an approver again each time. An admin enables it per entitlement. Once enabled, an approved user can reactivate that access on demand until their authorization expires.

The first request for a self-provisioning entitlement goes through the normal approval workflow. Approval grants the user an eligibility: a record that the user is authorized to self-provision the entitlement for a set duration. While that eligibility is live, the user can activate the entitlement again at any time, and Trustle grants it automatically. Activation goes through the normal request flow but auto-approves.

  • Self-provisioning needs one initial approval. After that, reactivation needs no approver.
  • Each activation is capped at a maximum duration, set on the entitlement’s policy.
  • The eligibility itself expires after its authorization window. After it expires, the next request goes through manual approval again.
  • Self-provisioning is not available on an entitlement that uses fully automatic, department-based approval. It works with manager approval, group-member approval, quorum approval, and two-level approval.

Self-provisioning differs from a plain approval workflow: a plain workflow asks an approver every time a user requests access. Self-provisioning asks once, then lets the user reactivate within the window on their own.

Self-provisioning also differs from standing access. Standing access has no expiration; it persists until someone removes it. Self-provisioned access always expires, and the user must reactivate it to keep working.

  • You need an org admin role to enable self-provisioning on an entitlement or to convert standing access to self-provisioning.
  • The entitlement’s approval workflow must support self-provisioning: manager, group-member, quorum, or two-level approval.

Step 1: Open the entitlement’s approval policy

Section titled “Step 1: Open the entitlement’s approval policy”

Go to the entitlement’s settings and open its approval policy tab.

Turn on the Self-Provisioning toggle. Its help text reads Automatically grant access after the first manual approval?.

Set the Authorization Window, for example 90 days. Its help text reads After first approval, how long will users be permitted to self-provision?. Trustle shows a summary: once approved, the user’s access requests, up to the maximum request duration, auto-approve for the length of this window.

Save the policy. The per-activation cap comes from the entitlement’s maximum request duration setting. The authorization window must be longer than the per-activation cap: the policy rejects a window that is shorter than or equal to it.

Convert standing access to self-provisioning

Section titled “Convert standing access to self-provisioning”

An admin can convert a user’s existing standing access to self-provisioning instead of waiting for the user to request it again.

  1. Open the user’s membership on the entitlement and choose Convert to Self-Provisioning.
  2. If the entitlement has no self-provisioning policy yet, Trustle shows Self-provisioning is not enabled for this entitlement and offers Configure Policy to set one up first.
  3. If the policy is set, the dialog shows the Authorization window and the Per-activation grant, and confirms that the user’s current access is capped at the per-activation grant. Click Convert.

Converting caps the user’s current access at the per-activation duration. The user can reactivate it at any time during the authorization window without admin approval.

  • A per-activation grant cannot exceed 365 days.
  • An authorization window cannot exceed 730 days.
  • The per-activation grant must always be shorter than the authorization window. Trustle enforces this so the window that authorizes reactivation always outlasts a single grant.

On the My Access page, a self-provisioned entitlement that is currently active appears in the Self-Provisioned section, with a description of “Currently granted access. Ends when the session expires.” Each row shows the entitlement, the reason given on the original request, and the time remaining, with an Extend and an End Now button.

  • Extend requests more time on the current activation, up to the policy’s per-activation limit.
  • End Now deprovisions the access immediately. The user can reactivate it later if their eligibility is still live.

When a self-provisioning eligibility exists but is not currently active, the user can activate it from the request catalog. Trustle grants it without routing it to an approver.