← Back to Work
Process file · Ops Ops

What’s inside: access rules · routing

A folder request queued beside Friday's leaver

The question this file answersHow much of our IT queue is 'add me to the folder' — and who is checking the leavers behind it?

Fits: SaaS and IT teams handling 50–500+ tickets a day.

Typical day

What the desk looks like today

Typical, from the software playbook (support) — mid-size SaaS and IT firms see 50–500+ tickets a day, access requests among them, uncounted separately. VPN, SaaS seats and 'add them to the folder' share the queue with a real joiner or leaver. Worst at quarter-end and on a new hire's first day.

What changes

What Monday looks like after

Monday morning, the service desk's queue is the new roles, the privileged asks and the leaver from Friday, not a page of folder requests. The approver still approves; the retyping into one admin console after another is what stops.

Typical, not a measured client result. Every figure here comes from the playbook source named below.

Known roles

catalogue roles granted, the rest to a person — a variant of our IT-ticket file; no published figure for access requests

Before: VPN and folder requests queue with true joiners and leavers. After: known roles are granted from the catalogue and every leaver and new role reaches a named person. Access requests have no figure of their own; the L1 range is on the IT-ticket file.

No published figure for this desk. The range lives on the parent file: Known issues from the knowledge base; outages to engineers →

How this file is built

Access-request handling has no separate published figure. Gartner (2023) and Freshworks/Zendesk (2023) measure L1 IT support as a whole, and their range is quoted on the parent file only. Not a security-compliance claim.

What we install

What we put in front of the systems you already run

Your ticketing and identity tools stay — Jira Service Management, Zendesk, Freshdesk and your directory, or whatever you run. The IT-ticket triage build is restricted to access requests:

  1. each request is classified — a known role in your catalogue, a new or unusual role, a revoke
  2. known-role requests are matched to the requester's job and approver in the directory and, if in policy, granted through the tool's API, with the ticket updated
  3. new roles, privileged access and every leaver go to a named person with the requester's current entitlements listed.
What stays human — and what this will not do

New roles. Segregation of duties. Offboarding that is really security. Anything identity must own.

Not a security-compliance claim.

What can go wrong — and what we do about it

Without a maintained role catalogue nothing can be 'known', and the first weeks go on writing one — that is audit work, not a feature. Segregation-of-duties conflicts and privileged access are never auto-granted; if your directory does not mark them, the rule cannot either. The Gartner and Freshworks/Zendesk figures on the parent file are about L1 tickets in general; there is no published figure for access management.

What it costs to get there

The path: free 60-second estimate → free 20-minute review → paid audit of this one process (€1.5–3K, typically two weeks) → pilot with your people in the loop (€10–20K, weeks, not quarters). No transformation programme. Prices are public, on the services page →

Scoped in the audit — the playbook has no estimate for this exact desk.

This is about you if…
What does this mean in euros?

That depends on your volumes and wage costs — this page will not invent the number. The free 60-second estimate runs that calculation from your answers, with every multiplier sourced.

Get your free savings estimate 60 seconds · no sales call Or write first → Map an ops process like this one — free, 60 seconds →

Not a named Aperanda client. Process file · Ops.

Short process file. Same build as its parent file; the playbook has no separate volume or benchmark for this desk.

All process files