Admin Guides / Access bundles
Build a bundle
Create an access bundle in the Admin Workspace, take it through pre-approval and make it live.
Administrators build bundles directly in the Admin Workspace, with no approval of their own. Anyone else proposes one with a request: see Propose a bundle.
1. Create the bundle
Open Catalog > Access bundles in the Admin Workspace and create a bundle. It starts as a Draft.
| Field | What to enter |
|---|---|
| Name | The name requesters see, usually the job, such as Accounts payable officer. Lifecycle integrations find bundles by name, so choose one that will last. |
| Description | What the bundle gives and who it is for |
| Owner | The person responsible for what it contains |
| Bundle type | Requestable, or Birthright for bundles your joiner process grants |
| Available for | User criteria for who it can be requested for. Empty means everyone. |
| Approval policy | How requests for it are approved. Empty uses the instance default. |
| Automated in the identity system | Tick when your identity system gives this whole bundle by its own rules |
2. Add the access
Add entitlements on the bundle's related list. To start from what someone already has, set Copy access from to a person and select Copy access from user. Their current access is added to the draft; anything that cannot be in a bundle is skipped and listed.
Entitlements that cannot be in a bundle: deprecated or retired ones, ones that must have an end date, and PIM-managed groups.
3. Submit for pre-approval
Select Submit for pre-approval. The bundle moves to Pending pre-approval, and each entitlement's owner and approvers are asked, by email, whether their entitlement may be included: Access bundle items waiting for your approval. They decide with Approve inclusion or Reject inclusion, which entitlement owners can do with the requester role.
If nobody is found to decide an entitlement, an administrator decides it from Catalog > Bundle entitlements: pending pre-approval.
While a bundle is pending:
- Withdraw returns it to draft so you can edit it. Decisions already made are kept, so nobody is asked again about those entitlements when you resubmit.
- Resubmit for pre-approval on a rejected entitlement asks its owner again.
- Remove from bundle takes an entitlement out. In a draft it is deleted; later it is kept as inactive history.
4. Activate
When nothing is waiting for a decision, the owner gets Your access bundle is ready to activate, and so do the administrators who review bundles if the owner is not one. Select Activate. You cannot activate a bundle while any entitlement is pending or rejected.
An active requestable bundle appears on the Access Bundles form for everyone its audience allows. An active birthright bundle can be granted by your joiner process.
Only a draft can be deleted. Once a bundle has been submitted, it is retired rather than deleted.