Day 14

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/19

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 4:15 PM on 8/17/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

20 Terms

1
New cards

How would you explain "access" using the keys-to-a-building analogy?

Access is a "key" that lets you open a digital "door," such as a file, folder, or database; just like a physical key, it should only go to people who need it and only last as long as they need it.

2
New cards

Why do companies bother with a formal access request and approval process instead of granting access freely?

Two main reasons: security (keeping unauthorized people out of sensitive information) and compliance (meeting legal requirements like HIPAA or SOX, which require proof that only the right people can see sensitive data).

3
New cards

How is SailPoint described as a "digital gatekeeper"?

It's compared to a smart security guard who checks ID badges, calls the right supervisor for approval, and keeps a logbook of every door opened, automating who can access what across a company.

4
New cards

Can you walk through the five steps of the access request lifecycle?

Submit (the request is filled out and sent), Queue (it waits for the right approver), Approve (a decision-maker says yes, no, or asks for more information), Provision (the access is actually switched on), and Confirm & Audit (everyone is notified and it's written down).

5
New cards

What does it mean for a request to be "in the queue," and why does that step matter?

The request doesn't disappear after submission; SailPoint automatically determines who needs to approve it and places it in that approver's personal to-do list, and nothing moves forward until a person reviews it.

6
New cards

What are the three roles involved in every access request workflow?

Requester (the person asking for access), Approver (the person who says yes or no), and Fulfiller (the system or person that actually grants the access once approved).

7
New cards

What's the difference between a simple workflow and a multi-step workflow?

A simple workflow involves just one request and one approver, suited to low-risk access like a shared calendar, while a multi-step workflow involves several approvers and checks in a row, used for sensitive systems like payroll.

8
New cards

What is an approval chain, and why might more than one signature be required?

An approval chain is the ordered list of people who must say yes before access is granted; chains exist so no single person carries all the responsibility for a risky decision, and if any link says no, the request stops.

9
New cards

What is the difference between a single-level and a multi-level approval chain?

A single-level chain has just one approver, appropriate for low-risk requests, while a multi-level chain strings together two or more approvers in sequence, appropriate for sensitive data.

10
New cards

Who are the typical roles that can appear in an approval chain?

The direct manager (knows if the access fits the job), the resource/application owner (responsible for that system), and the security or compliance team (checks for policy or legal issues on highly sensitive requests).

11
New cards

What is a conditional or risk-based approval chain?

An approval chain that automatically changes based on how risky the request is, such as automatically adding a Security Team step when someone requests admin rights to a financial system, rather than always using a fixed chain.

12
New cards

What is a role in the context of role assignment, and what analogy is used to explain it?

A role is a bundled set of access rights that matches a job, compared to a pre-packed toolkit handed to a new electrician on day one instead of requesting each tool separately; this bundling approach is called RBAC (Role-Based Access Control).

13
New cards

What is the difference between a birthright role and a requestable role?

A birthright role is access every employee in a certain job automatically receives on day one, like company email, while a requestable role is extra access an employee can ask for later, like a finance reporting tool, going through the request-and-approval workflow.

14
New cards

How does role assignment speed up the access request process?

Instead of an approver reviewing ten separate access items one at a time, they review and approve one single bundled role, which reduces mistakes and makes future audits simpler.

15
New cards

What is escalation, and what everyday scenario illustrates it?

Escalation means automatically moving a stuck request up to someone else when it isn't handled in time, illustrated by a manager being on vacation for several days so the request is automatically sent up to the manager's boss instead.

16
New cards

What role does an SLA play in triggering an escalation?

Companies set a Service-Level Agreement, such as "approve within 48 hours," and if that timer runs out with no response, SailPoint automatically escalates the request to a backup approver.

17
New cards

Why might a company set up a reminder notification before an escalation actually happens?

To give the original approver a chance to respond before the request moves on, functioning like a gentle nudge before the deadline "alarm" goes off.

18
New cards

What is the purpose of an audit trail created during the access request process?

It's a permanent, timestamped log of who requested access, who approved it, and exactly when each step happened, which the company can use to prove to regulators or auditors that the proper process was followed.

19
New cards

Why are vague access requests discouraged?

A vague request slows down the approver's decision, while a specific, clear request makes it faster and easier for the approver to judge whether the access is appropriate.

20
New cards

Why does the general rule "the more sensitive the resource, the longer the workflow" make sense?

More sensitive systems carry more risk if access is granted incorrectly, so additional approval steps and stricter scrutiny help ensure that only the right people get access to high-risk data.