---
title: Request Access
description: >-
  Let users request the access they need directly from a permission-denied page,
  with manual or automatic approval workflows for administrators.
breadcrumbs: Docs > Account Management > Access Control > Request Access
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Request Access

{% callout %}
Request Access is in Preview and is rolling out gradually. It may not be available in your organization yet.
{% /callout %}

## Overview{% #overview %}

Getting access to a feature in Datadog could mean knowing who to ask, filing a ticket, and waiting for a response. For organizations managing many roles and users, this slows users down and creates manual work for administrators.

Request Access lets a user ask for the permission they need directly from the page where they were blocked, with a justification for the request. Administrators can review and approve these requests from a central queue, or configure specific roles to be granted automatically. Every request, decision, and justification appears in [Audit Trail](https://docs.datadoghq.com/account_management/audit_trail.md), so access changes stay traceable without a support ticket.

## Enable or disable Request Access{% #enable-or-disable-request-access %}

**Note**: You must have the `user_access_manage` permission.

To enable manual or auto-approval requests for your organization, navigate to [Organization Settings](https://app.datadoghq.com/organization-settings/) and select Access Controls, then create the corresponding configuration. See Configuring access requests as an administrator for setup details.

To disable manual or auto-approval requests, delete all corresponding configurations. Disabling is especially relevant if you manage access through a separate internal access elevation process.

## Requesting access as an end user{% #requesting-access-as-an-end-user %}

### From a permission-denied page{% #from-a-permission-denied-page %}

When you navigate to a page that requires a permission you don't have, Datadog shows a 403 permission-denied page. If your organization has a manual approval or auto-approval configuration enabled for a role that includes that permission, a Request Access button appears on the page.

1. Click Request Access.
1. Enter a justification for the request.
1. Submit the request.

If a matching auto-approval configuration exists, Datadog grants access within a minute and notifies you. Otherwise, Datadog sends the request to your organization's approvers for manual review.

### From the Roles page{% #from-the-roles-page %}

You can also request a role directly, without first reaching a permission-denied page.

1. Navigate to [Organization Settings](https://app.datadoghq.com/organization-settings/) and select Roles.
1. Find the role you want and open its details panel.
1. Click Request Access.
1. Enter a justification and submit.

Direct role requests follow the same approval and auto-approval rules as requests made from a permission-denied page.

### For an asset{% #for-an-asset %}

You can also request access to assets like Monitors and Dashboards if your admin has configured auto-approval rules.

To request access to an individual asset, go to the asset and click Request Access. If you already have viewer access and want to request a higher permission level, open the existing sharing settings for the asset instead.

## Configuring access requests as an administrator{% #configuring-access-requests-as-an-administrator %}

Navigate to [Organization Settings](https://app.datadoghq.com/organization-settings/) and select Access Controls to configure and manage all access request settings. You need the `user_access_manage` permission to access this page.

### Manual approval{% #manual-approval %}

Manual approval escalates a request to a list of approvers, who can approve or deny it. Your organization supports one manual approval configuration, and enabling it turns on manual requests for every role in the organization.

1. Navigate to [Organization Settings](https://app.datadoghq.com/organization-settings/) and select Access Controls.
1. Create a manual approval configuration.
1. Select the users who can approve requests. Only users with the `user_access_manage` permission are eligible.

If you don't designate approvers, every user with `user_access_manage` can still approve or deny requests, but none of them receive email notifications.

Approvers review pending requests from the Pending Requests tab on the Access Controls page, where each request shows the requester, the role, and the requester's justification. Datadog emails the requester after an approver takes action.

### Auto-approval for roles and permissions{% #auto-approval-for-roles-and-permissions %}

Auto-approval lets eligible users unblock themselves immediately, without a manual review step.

1. Navigate to [Organization Settings](https://app.datadoghq.com/organization-settings/) and select Access Controls.
1. Create an auto-approval configuration. Your organization supports up to 10 configurations.
1. Select the roles this configuration auto-approves.
1. Optionally, restrict which users, teams, or roles can trigger this configuration. If you leave this field empty, the configuration applies to all users.

### Temporary access (Preview){% #temporary-access-preview %}

An auto-approval configuration can grant a role for a limited time instead of permanently. Set the assignment duration when you create the configuration: 1 hour, 1 day, 1 week, 30 days, or permanent.

When a temporary role assignment expires, Datadog revokes it within 5 minutes. You can view a user's active and expiring role assignments from their profile page, or from [Organization Settings](https://app.datadoghq.com/organization-settings/) under Users.

### Auto-approval for assets{% #auto-approval-for-assets %}

Asset auto-approval extends the same self-service model to individual resources. Your organization can auto-approve viewer or editor access for the following resource types:

- Case Management projects
- Dashboards
- Monitors
- Notebooks
- Reference Tables
- Synthetic tests
- Synthetic global variables
- Synthetic private locations

Enabling a resource type applies the configuration to every resource of that type. Like role and permission auto-approval, asset auto-approval configurations can be scoped to specific users, teams, or roles. Configure requester scoping separately for each access level. For example, you can allow all users to request viewer access to dashboards while limiting editor access requests to a specific team.

## Audit Trail{% #audit-trail %}

Datadog logs every access request in [Audit Trail](https://docs.datadoghq.com/account_management/audit_trail.md), including the requester, the role or resource requested, the justification, and the outcome. Use Audit Trail to review access history without relying on ticket or chat history.

## How role selection works{% #how-role-selection-works %}

When a user requests access because of a missing permission, Datadog selects the role that satisfies the required permission with the fewest total permissions. If several roles tie on permission count, Datadog picks the first one alphabetically. This selection method limits over-provisioning without requiring an administrator to map every role to every possible access scenario in advance.

## Limitations{% #limitations %}

- Your organization supports one manual approval configuration and up to 10 auto-approval configurations.
- If no role in your organization contains the required permission, the user has no option to request access for it.
- Requests grant a full role, not a single permission. If you need finer-grained control, create a role scoped to only the required permissions and set it as the auto-approved or manually approved option.

## Further reading{% #further-reading %}

Additional helpful documentation, links, and articles:

- [Permissions](https://docs.datadoghq.com/account_management/rbac/permissions.md)
- [Granular Access](https://docs.datadoghq.com/account_management/rbac/granular_access.md)
- [Access for Enterprises](https://docs.datadoghq.com/getting_started/access_for_enterprises.md)
