How to Answer User Access Provisioning Questions

Your customer asked: “How do you provision user access?”

The short answer

Explain how a person receives access, who approves it, and how the access level is chosen. A written procedure is useful, but do not claim a formal approval workflow if access is actually granted informally.

Educational guidance only. This page does not determine what is true about your company and does not create a security, compliance, testing, or certification claim.

What the customer is really asking

Understand the question before you answer it.

The customer is trying to understand whether new access is controlled rather than simply handed out. They may care about who requests access, who approves it, whether job responsibilities influence permissions, and who actually creates the account.

How to answer accurately

Start with the version that matches reality.

1

If you have a documented workflow

Describe the request, approval, and account-creation steps at a high level. Keep the answer aligned with the process your team really follows.

2

If the process is informal but consistent

Describe the current practice plainly. A small company may have a manager and administrator handle access without a ticketing system; do not turn that into an automated workflow in your answer.

3

If different systems work differently

State the important differences rather than forcing one universal process onto every application.

A useful answer structure

Status → scope → current practice → supporting information. Start with the direct answer, narrow it to what you can verify, explain how the practice works, and reference evidence only when that evidence actually exists.

Evidence that may help

These are examples, not requirements and not proof that your company has the practice. Use only evidence that really exists and is appropriate to share.

  • Access request or onboarding records
  • Manager approvals
  • Identity-provider or application audit records
  • User provisioning procedure

What not to say

  • That access is role-based if permissions are actually assigned case by case.
  • That every request is formally approved unless records support that.
  • That a written onboarding checklist proves the access control operated.

How Oredra handles this

Answer it once. Keep the truth behind the answer.

Oredra helps keep the stated onboarding practice separate from the evidence that shows individual access requests were actually handled that way.

Inside Oredra, a written policy, stated company practice, implemented control, available evidence, tested control, and independent certification remain distinct. Oredra uses approved information to draft future answers and flags questions that the approved profile cannot support.

Authoritative references

Oredra uses primary guidance where a technical or assurance concept benefits from verification. These references do not determine your company's answer.

Related questionnaire questions