> ## Documentation Index
> Fetch the complete documentation index at: https://docs.formal.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Approve Access Requests

> Review employee requests for MCP servers and policy exceptions in the Control Plane

## Overview

[Access Requests](https://app.formal.ai/access-requests) is the approval queue for employee requests. Employees ask for access in the employee Catalog at [catalog.formal.ai](https://catalog.formal.ai). Admins approve or reject each request in the Control Plane, and Formal applies the approved change.

<Note>
  Access Requests is separate from the Slack approval flow built with
  [Forms](/docs/guides/configuration/forms) and
  [Workflows](/docs/guides/configuration/workflows). Both can run in the same
  organization.
</Note>

## What Employees Can Request

| Request | Where the employee starts | What approval does |
| - | - | - |
| A new MCP server | **Request access** for an MCP server that isn't in the Catalog. They enter a **Name**, the **MCP URL**, and a **Reason**. | Adds the server to the Catalog. You can choose its Space. |
| Access to an MCP server in the Catalog | **Request access** on the server's page | Adds the requester to the server's access controls |
| A one-time exception | **Request access** on an action that a policy blocked, then **One-time exception** | Creates a one-off [policy suspension](/docs/guides/policies/suspensions) for that action |
| A time-bound exception | **Request access** on a blocked action, then **Time-bound access** and a **Duration** | Creates a time-bound policy suspension. Durations range from 30 minutes to 7 days. |
| Permanent access | **Request access** on a blocked action, then **Permanent access** | If an MCP server's Catalog access controls blocked the action, adds the requester. For other policies, records the approval only: edit the policy yourself. |

Employees see blocked actions under **Activity** in the employee Catalog. They follow their requests on its **Requests** page.

## Review a Request

<Steps>
  <Step title="Open the queue">
    Go to [Access Requests](https://app.formal.ai/access-requests). Filter by **Status**: **Pending**, **Approved**, or **Rejected**. The list shows the resource, the requester, the requested access, when it was submitted, and its status.
  </Step>

  <Step title="Open the request">
    Click a request to see its details and the requester's reason.
  </Step>

  <Step title="Add a reason (optional)">
    Under **Decision for this request**, add context for the requester and the audit trail.
  </Step>

  <Step title="Decide">
    Click the approve button, or **Reject Request**. The approve button names the outcome:

    * **Approve and create** for a new MCP server
    * **Approve MCP access** for an MCP server in the Catalog
    * **Approve one-time exception**, **Approve time-bound exception**, or **Approve permanent exception** for policy exceptions
  </Step>
</Steps>

Formal applies the change, then marks the request **Approved**. The duration of a time-bound exception is the one the employee chose. You can't change it during approval.

**Verify:** The request moves to **Approved**. For an exception, the suspension appears in [Policy Suspensions](https://app.formal.ai/policies?tab=suspensions).

<Warning>
  Formal doesn't send notifications for Access Requests. Check the queue
  regularly, or build a Slack approval flow with
  [Workflows](/docs/guides/configuration/workflows) for time-sensitive requests.
</Warning>

## Permissions

The Access Requests page requires the **Resource** permission. Approvals that create suspensions or change access controls also require the **Policies** permission.

## API

Use `core.v1.ApprovalService` to work with requests programmatically:

| Method | Purpose |
| - | - |
| `ListApprovalRequests` | List requests, for example to build a report |
| `UpdateApprovalRequest` | Record a decision |
| `ListAccessRequests` | List requests made by a user |
| `CreateAccessRequest` | File a request on behalf of a user. Only machine users can call it, and they must set `requester_user_id`. |

`UpdateApprovalRequest` only records the decision. It doesn't create the MCP server, the access change, or the suspension. Approve from the Control Plane to apply the change.

## Next Steps

<CardGroup cols={2}>
  <Card title="Policy Suspensions" icon="clock-rotate-left" href="/docs/guides/policies/suspensions">
    Manage the exceptions that approvals create
  </Card>

  <Card title="AI Governance" icon="robot" href="/docs/guides/ai-governance/overview">
    Learn how the Catalog and access controls work
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.