## TL;DR
The form needs exactly five things: who (identity), what (system and access level), why (business justification), how long (end date), and who approves (sponsor). Everything else is optional. Route automatically to the sponsor first, then to IT. A form missing any of the five generates back-and-forth instead of access.

## The error
```text
(Process design; no error.)
```

## Steps
1. Define the required fields: requester identity (auto-filled from SSO), target user if different, system/application, access level or role, business justification (free text, required), start and end date, sponsor/approver. Expected: form drafted.
2. Build approval routing: sponsor approves first, then the system owner for sensitive systems, then IT provisions. Expected: routing configured. IT should never be the first approver.
3. Add guardrails: end date defaults to 90 days for contractors, justification minimum length, duplicate-request detection. Expected: configured. Defaults shape behavior more than policy docs do.
4. Pilot with one team for two weeks and read every ticket. Expected: friction points found. Fix the form, not the users.
5. Publish with a one-paragraph guide: what to request, who approves, how long it takes. Expected: announced. A good form with no guide still confuses people.

## When to use
- Building a new intake process
- Fixing a form that generates incomplete tickets

## When not to use
- Emergency access (use the break-glass process)
- Approving or provisioning (separate steps)

## Compatibility
- ServiceNow, Jira Service Management, or any ITSM with forms and workflows

## Variants
### High-volume simple requests
Offer a catalog of pre-approved bundles (e.g. "sales starter pack") that skip sponsor approval.
### Sensitive systems
Add a second approver (system owner) and a justification review step.

## Why it happens
Access requests fail on missing information, not on technology. The five fields exist because every provisioning conversation eventually needs all five answers.

## Edge cases
- Allow requesting for someone else (managers request for new hires); validate the target identity.
- Keep the form short; every optional field you add reduces completion.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_AUGCH6xlloWoY71L4j51Vw
