Self-provisioning
Self-provisioning lets a user activate an entitlement themselves after one manual approval, without asking an approver again each time. An admin enables it per entitlement. Once enabled, an approved user can reactivate that access on demand until their authorization expires.
How it works
Section titled “How it works”The first request for a self-provisioning entitlement goes through the normal approval workflow. Approval grants the user an eligibility: a record that the user is authorized to self-provision the entitlement for a set duration. While that eligibility is live, the user can activate the entitlement again at any time, and Trustle grants it automatically. Activation goes through the normal request flow but auto-approves.
- Self-provisioning needs one initial approval. After that, reactivation needs no approver.
- Each activation is capped at a maximum duration, set on the entitlement’s policy.
- The eligibility itself expires after its authorization window. After it expires, the next request goes through manual approval again.
- Self-provisioning is not available on an entitlement that uses fully automatic, department-based approval. It works with manager approval, group-member approval, quorum approval, and two-level approval.
Self-provisioning differs from a plain approval workflow: a plain workflow asks an approver every time a user requests access. Self-provisioning asks once, then lets the user reactivate within the window on their own.
Self-provisioning also differs from standing access. Standing access has no expiration; it persists until someone removes it. Self-provisioned access always expires, and the user must reactivate it to keep working.
Before you start
Section titled “Before you start”- You need an org admin role to enable self-provisioning on an entitlement or to convert standing access to self-provisioning.
- The entitlement’s approval workflow must support self-provisioning: manager, group-member, quorum, or two-level approval.
Configure self-provisioning
Section titled “Configure self-provisioning”Step 1: Open the entitlement’s approval policy
Section titled “Step 1: Open the entitlement’s approval policy”Go to the entitlement’s settings and open its approval policy tab.
Step 2: Turn on Self-Provisioning
Section titled “Step 2: Turn on Self-Provisioning”Turn on the Self-Provisioning toggle. Its help text reads Automatically grant access after the first manual approval?.
Step 3: Set the authorization window
Section titled “Step 3: Set the authorization window”Set the Authorization Window, for example 90 days. Its help text
reads After first approval, how long will users be permitted to
self-provision?. Trustle shows a summary: once approved, the user’s
access requests, up to the maximum request duration, auto-approve for the
length of this window.
Step 4: Save the policy
Section titled “Step 4: Save the policy”Save the policy. The per-activation cap comes from the entitlement’s maximum request duration setting. The authorization window must be longer than the per-activation cap: the policy rejects a window that is shorter than or equal to it.
Convert standing access to self-provisioning
Section titled “Convert standing access to self-provisioning”An admin can convert a user’s existing standing access to self-provisioning instead of waiting for the user to request it again.
- Open the user’s membership on the entitlement and choose Convert to Self-Provisioning.
- If the entitlement has no self-provisioning policy yet, Trustle shows Self-provisioning is not enabled for this entitlement and offers Configure Policy to set one up first.
- If the policy is set, the dialog shows the Authorization window and the Per-activation grant, and confirms that the user’s current access is capped at the per-activation grant. Click Convert.
Converting caps the user’s current access at the per-activation duration. The user can reactivate it at any time during the authorization window without admin approval.
Duration limits
Section titled “Duration limits”- A per-activation grant cannot exceed 365 days.
- An authorization window cannot exceed 730 days.
- The per-activation grant must always be shorter than the authorization window. Trustle enforces this so the window that authorizes reactivation always outlasts a single grant.
What users see
Section titled “What users see”On the My Access page, a self-provisioned entitlement that is currently active appears in the Self-Provisioned section, with a description of “Currently granted access. Ends when the session expires.” Each row shows the entitlement, the reason given on the original request, and the time remaining, with an Extend and an End Now button.
- Extend requests more time on the current activation, up to the policy’s per-activation limit.
- End Now deprovisions the access immediately. The user can reactivate it later if their eligibility is still live.
When a self-provisioning eligibility exists but is not currently active, the user can activate it from the request catalog. Trustle grants it without routing it to an approver.