Request and manage privileged access
Submit a time-bound privileged-access request and review its state without bypassing approval or separation-of-duty controls.
Audience, roles, and scope
User-facing privileged-access requests and status review; administrator policy and assignment remain outside this article.
Who this is for
- Users eligible to request elevated access
Roles
- Requester
- Authorized approver
Before you begin
- Eligibility under organization policy
- A documented business reason and intended duration
Article tags
- privileged-access
- approval
- roles
- security
Procedures
Follow the sequence and stop when identity, authorization, target, or result differs from the article.
Request elevated access
Ask only for the minimum access and duration required.
- 1Define the task
Identify the exact privileged activity, target scope, business reason, and minimum required time window.
- 2Submit the request
Select only an eligible access option, enter a non-sensitive justification, and verify the request before submission.
- 3Review and close
Wait for an explicit approved state before acting; when work ends, confirm expiry or follow the organization revocation process.
The request has a traceable state and privileged work occurs only after approval and within scope.
Security and data handling
- Use only the identity, tenant, role, and data scope approved for the task.
- Verify targets and expected effects before saving, sending, publishing, exporting, deleting, or approving.
- Keep secrets and regulated data out of screenshots, URLs, free-text diagnostics, and ordinary support messages.
- Do not approve your own request unless organization policy explicitly permits it.
- Privileged approval does not expand data-handling authorization beyond the documented task.
Known limitations
- The interface does not guarantee eligibility or approval; policy, tenant configuration, and approver availability control the outcome.
- Emergency-access procedures, if any, are organization-specific.
Troubleshooting
You cannot open My Vianordis
Likely cause: The session expired, the account is not entitled, or the required tenant or role claim is missing.
- Open the service through the approved Vianordis entry point and sign in again.
- Confirm the intended organization, tenant, and account are in use.
- If access remains denied, record the time and request an entitlement check; do not attempt direct-URL bypasses.
A documented control or navigation item is not visible
Likely cause: The current role, subscription, tenant configuration, release status, or feature flag does not expose it.
- Confirm the audience, role, prerequisites, and limitations in this article.
- Refresh after a new sign-in and verify the correct tenant context.
- Ask the responsible administrator whether the capability is enabled before reporting a defect.
A saved change or background result is not visible
Likely cause: Validation failed, processing is incomplete, the view is stale, or the feature is locally simulated rather than persisted.
- Review inline validation, status indicators, filters, and the selected tenant or workspace.
- Refresh once and search by a stable identifier before repeating the action.
- Do not repeat irreversible or externally visible actions until the first operation's state is known.
Source verification
Request fields, approval states, and user-facing controls were reviewed in the pinned source.
Reviewed paths at 1f3e2e3
src/app/(my)/access/page.tsxsrc/components/pam/AccessPageClient.tsxsrc/components/pam/RequestModal.tsxsrc/components/pam/ActiveGrantsWidget.tsx
Contact support
Contact support when
- A repeatable My Vianordis error blocks an approved task
- Expected access, tenant scope, data, or status appears incorrect
- A security, privacy, financial, compliance, or data-loss concern is suspected
Include
- The page, action, expected result, and exact error text
- The time of occurrence with time zone and whether it is reproducible
- Your tenant, role, browser, and sanitized record or correlation identifier
- The troubleshooting steps already completed
Never include
- Passwords, access tokens, API keys, recovery codes, session cookies, or private keys
- Unredacted personal, financial, health, student, employee, or other regulated data
- Confidential documents or message bodies unless support provides an approved secure channel