1. User requests access
The user clicks Request Access on the record. If configured, they must provide a reason and/or ticket number before the request is submitted.
2. Approver is notified
Approvers receive a real-time notification across all Keeper clients — desktop, web and mobile — and can approve or deny from any of them.
3. Access is granted
Once approved, the record unlocks for the user and the access timer starts, either immediately upon approval or when they launch their first connection, depending on your configuration.
4. MFA check (if enabled)
Before the user can launch a connection or start a tunnel, they must complete multi-factor authentication using their Keeper account's MFA method.
5. Session runs
The user works within their approved access window. If Single-User Mode is on, no other user can check out the resource while it's in use.
6. Access is revoked
When the time limit is reached, access is automatically revoked. The user can also check in manually when finished. Approvers can force a check-in at any point.