Managing Access Requests
Frappe Cloud follows a permission-based access model to protect customer resources. By default, no one including Frappe employees can access your resources without explicit approval. Access is granted only when requested and is automatically limited to a specific period of time.
The access control system is still under active development. While fully functional, you may occasionally encounter minor issues as improvements continue to be rolled out.
Why Access Requests Are Required
Protecting customer data is one of Frappe Cloud’s highest priorities. To maintain strong security and privacy, access to customer resources is denied by default for everyone, including Frappe support agents.
Whenever support assistance is required, an agent must submit an access request explaining the reason and requesting only the permissions necessary to resolve the issue. The customer can then approve or reject the request, ensuring complete control over who can access their resources and for how long.
Managing Access Requests as a Customer
Customers can review and manage all incoming access requests directly from the Access Requests page available in the Frappe Cloud dashboard sidebar.
Each request includes important details such as:
- The resource being requested.
- The reason for the request.
- The request creation time.
- The access expiration time.
- The current request status.
Requests are automatically sorted by their most recent updates, making it easy to review the latest activity first.
Viewing Request Details
Selecting a request opens a detailed view containing additional information, including:
- All requested resources.
- Requested permissions.
- Any notes provided by the support agent.
Approving or Rejecting Requests
Pending requests can be either approved or rejected.
- Approve to grant temporary access for the requested duration.
- Reject to deny access completely.
Once approved, the agent receives only the permissions requested and only until the specified expiration time.
Revoking Previously Granted Access
Customers can revoke access at any time, even before it expires. Revoking immediately removes the agent’s permissions for the associated resource.
If multiple approved requests exist for the same resource, every active request must be revoked before access is completely removed.
Notifications
Whenever a support agent submits or updates an access request, customers receive:
- Email notifications.
- In-app notifications within the Frappe Cloud dashboard.
These notifications keep customers informed throughout the entire approval process.
Managing Access Requests as a Support Agent
Support agents request access directly from the page of the resource they need to troubleshoot. Clicking the Request Access button opens a request form where the required information can be entered.
Request Only What You Need
Agents should always request the minimum permissions necessary to complete the task. If additional permissions become necessary later, another request can be submitted.
Following the principle of least privilege helps maintain stronger security by limiting access to only what is required.
Tracking Access Requests
Agents receive both email and in-app notifications whenever the customer approves, rejects, or updates a request.
All incoming and outgoing requests can be monitored from the Access Requests page, allowing agents to easily track their current permissions.
Forfeiting Access
Once a support task has been completed, agents can voluntarily forfeit their granted access without waiting for it to expire.
This immediately removes their permissions and notifies the customer that access has been relinquished.
Viewing Current Access Status
Resources that have temporary access display an Unlock icon in the page header. Selecting this icon displays:
- Current permissions.
- Access expiration date and time.
- Options to request additional permissions if required.
Summary
Frappe Cloud’s access request system ensures that customer resources remain protected through explicit, time-limited permissions. Customers retain complete control over access approvals and revocations, while support agents can securely request only the permissions required to resolve issues. This approach provides greater transparency, stronger security, and improved customer trust throughout the support process.