Managing Support Access Requests
Frappe Cloud uses time-bound access controls to protect customer resources. By default, no one including Frappe support agents can access your sites, benches, or servers. Whenever support requires access, agents must submit a request, which customers can approve, reject, or revoke at any time.
Access control features are still under development. While fully functional, you may occasionally encounter minor issues or interface changes.
Why Access Requests Exist
Customer data security is one of the highest priorities on Frappe Cloud. Rather than allowing permanent administrator access, every support request follows the principle of least privilege.
- Support agents have no access by default.
- Access must be explicitly requested.
- Customers decide whether to approve or reject each request.
- Approved access automatically expires after the requested time period.
- Customers can revoke access at any time.
This approach ensures that your resources remain accessible only when necessary while maintaining complete transparency.
Managing Access Requests as a Customer
You can review and manage all incoming support access requests directly from your Frappe Cloud dashboard through the Access Requests page.
Viewing Requests
Each request includes important details, including:
- The resource being accessed (Site, Bench, Server, etc.).
- The reason provided by the support agent.
- The requested expiration time.
- The date and time the request was created.
Requests are automatically sorted by their most recent activity, making it easy to review pending requests first.
Viewing Request Details
Clicking any request opens a detailed view showing:
- Requested resources.
- Additional permissions being requested.
- Access duration.
- Reason for the request.
Approving or Rejecting Requests
For pending requests, you can:
- Accept the request to grant temporary access.
- Reject the request if access should not be granted.
Once approved, the support agent receives only the permissions requested and only for the approved duration.
Revoking Existing Access
If access is no longer required, you can revoke it immediately.
Revoking removes the agent’s permissions instantly.
If multiple approved requests exist for the same resource, each request must be revoked individually before access is completely removed.
Notifications
Customers receive both email and in-app notifications whenever:
- A new access request is submitted.
- A request is approved or rejected.
- An approved request is updated or revoked.
Apart from reviewing requests, no additional configuration is required. Your resources remain inaccessible until you explicitly grant permission.
Managing Access Requests as a Support Agent
Support agents must request permission before accessing any customer resource.
Requesting Access
Navigate to the required resource and click Request Access.
When submitting a request, provide:
- The reason access is required.
- The minimum permissions needed.
- The required access duration.
Only request permissions that are necessary for the current task. Additional permissions can always be requested later if required.
Tracking Requests
Support agents can monitor all submitted requests from the Access Requests page.
This page displays:
- Pending requests.
- Approved requests.
- Rejected requests.
- Expired requests.
Agents also receive email and in-app notifications whenever customers respond to their requests.
Forfeiting Access
Once work is complete, agents should voluntarily relinquish access by selecting Forfeit Access.
Doing so immediately removes their permissions and notifies the customer that access has been surrendered.
Viewing Current Permissions
Whenever an agent has temporary access to a resource, an unlock icon appears on the resource page.
Selecting this icon displays:
- Current permissions.
- Access expiration time.
- Option to request additional permissions.
- Option to extend or renew access.
How Access Works
- Support agent submits an access request.
- Customer receives email and dashboard notification.
- Customer reviews the requested permissions.
- Customer approves or rejects the request.
- If approved, temporary access is granted.
- Access expires automatically after the approved duration or can be revoked manually at any time.
Summary
Frappe Cloud’s access request system ensures that support access is secure, transparent, and fully controlled by the customer. Support agents cannot access customer resources unless explicit permission is granted, every request is time-limited, customers receive notifications for every change, and access can be revoked instantly whenever required. This permission-based model helps maintain strong security while allowing support teams to resolve issues efficiently when assistance is needed.