You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A user requests membership in a group; a reviewer approves or denies. Approval
grants the group through the normal Okta -> AD path (so nesting + ACLs apply),
and every step is audited -- access via a reviewable workflow, not a favour.
- requests.py: AccessRequest + RequestQueue
- engine: request_access / approve_request / deny_request (audited), state persisted
- cli: request, requests, approve, deny
- api: GET/POST /requests, POST /requests/approve, /requests/deny
- GUI: Requests view (queue + approve/deny buttons + file-a-request form),
demo + live backends; snapshot exports the group list + request queue
- 6 request tests (73 total, ruff-clean); browser-verified end-to-end
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01H9BehfGmiCrz3J15W18rc9
|**Access requests & approvals**| Self-service request → reviewer approve/deny → auto-provisioned through the normal Okta→AD path, audited | IT, managers, everyone |
130
131
|**Endpoints / devices**| Images + ships a managed laptop per role (encryption, MDM, MFA, Iru/Ansible); wipe & return at offboard | IT |
131
132
|**Compliance-gated access**| Training records (IACUC, biosafety…) that gate sensitive lab data; access auto-revokes when training lapses | Compliance, In-Vivo, IT |
132
133
|**SaaS & cost**| Who has a seat in what and **what it costs**; orphaned-seat detection; provisioned on onboard, reclaimed on offboard | IT, Finance |
@@ -265,6 +266,9 @@ labsuite train --user nrahman --training IACUC # complete a training (unloc
0 commit comments