Access request stuck in pending approval for days: how to unblock it
For customers waiting on an access request that has sat in "Pending" or "Awaiting approval" for days. This runbook helps you quickly identify whether the request is blocked by the wrong approver, missing required details, email delivery issues, policy rules, or an expired request, and shows the exact next action to take.
TL;DR — If your access request has been sitting unapproved for days, the most common reason is that it was sent to the wrong approver or the approver never received the notification email. Start by opening the request details in your provider's dashboard, confirm the assigned approver and request status, then either resend the approval notification or cancel and re-submit the request with the correct approver and business justification. Reading time: ~6 min
The scenario
It is Tuesday afternoon, you are trying to get access to a production project, shared mailbox, VPN, or admin dashboard, and your request still says "Pending approval" three days later. You already told your manager, the client is waiting, and the person who usually approves access says they "never saw anything come through." You open the portal again and the request is still there, unchanged, with no obvious error. At this point, you need to figure out whether the request is waiting on the wrong person, blocked by policy, or simply expired and forgotten.
Symptoms
- The request status in the dashboard shows one of these messages:
Pending approval Awaiting approval Submitted Waiting for approver In review - You do not receive any follow-up email after submission, or the approver says they did not receive one.
- The request detail page shows no progress for multiple days.
- The approver list is blank, incorrect, or shows someone who is out of office.
- Re-submitting the same request creates another pending request instead of granting access.
- You may see one of these messages on the request page:
Approval required before access can be granted Request missing required information Request expired Request denied by policy No eligible approver found - In some systems, the audit trail (activity log) shows events like:
Request created Approval notification sent Approval notification delivery failed Escalation not configured Request expired after 72 hours
Likely causes
| Cause | How common | Quick check |
|---|---|---|
| Request was routed to the wrong approver or no approver | Very common | Dashboard: Access Requests → open the request → Approver/Reviewer field |
| Approval email was not delivered or was filtered as spam | Very common | Dashboard: Access Requests → open the request → Activity/Audit log |
| Required fields were incomplete, so the request cannot move forward | Common | Dashboard: Access Requests → open the request → Details/Validation |
| Policy requires a different request type or stronger justification | Common | Dashboard: Access Requests → open the request → Policy/Reason shown on page |
| The request expired and needs to be re-submitted | Moderate | Dashboard: Access Requests → open the request → Status/Created time |
| The approver is unavailable and no backup/escalation is configured | Moderate | Dashboard: Access Requests → open the request → Assigned approver |
Step-by-step diagnosis
-
Open the request details and confirm the exact status.
- Menu path: in your provider's dashboard, go to
Access Requests → My Requests → select the stuck request. - This is your problem if you see:
Pending approval Awaiting approval In review - If the page instead shows
Expired, jump to Fixes → Expired request. - If it shows
Denied by policyor similar, jump to Fixes → Policy requires a different request type or stronger justification.
- Menu path: in your provider's dashboard, go to
-
Check who the request was sent to.
- Menu path: on the same request page, look for
Approver,Reviewer, orAssigned to. - This is your problem if the approver is blank, is the wrong person, or is someone unavailable.
- If so, jump to Fixes → Request was routed to the wrong approver or no approver or Fixes → Approver unavailable and no backup/escalation configured.
- Menu path: on the same request page, look for
-
Check the activity log for notification delivery.
- Menu path:
Access Requests → My Requests → select request → Activity,Audit log, orTimeline. - This is your problem if you see lines like:
Approval notification delivery failed Email bounced Notification suppressed - If yes, jump to Fixes → Approval email was not delivered or was filtered as spam.
- Menu path:
-
Check whether the form is incomplete.
- Menu path:
Access Requests → My Requests → select request → Details. - This is your problem if the page shows warnings such as:
Missing business justification Missing duration Missing ticket number Missing system owner - If yes, jump to Fixes → Required fields were incomplete.
- Menu path:
-
Check whether the request type matches the policy.
- Menu path: on the request page, look for
Policy,Reason,Validation, or any banner message. - This is your problem if you see messages like:
Admin access requires temporary elevation Production access requires break-glass workflow Permanent access not allowed for this resource MFA required before approval - If yes, jump to Fixes → Policy requires a different request type or stronger justification.
- Menu path: on the request page, look for
-
If everything looks correct, contact the approver with the request ID and ask them to open the request directly in the dashboard.
- Copy these details from the request page: request ID, resource name, submission time, and your justification.
- This is your problem if the approver confirms they were assigned but had no reminder, no escalation, or no visibility.
- Then jump to Fixes → Approver unavailable and no backup/escalation configured.
Fixes
Request was routed to the wrong approver or no approver
- In the dashboard, open
Access Requests → My Requests → select request. - If the system allows editing, change the approver on the request detail page.
- If it does not allow editing, cancel the request and submit a new one.
- When re-submitting, pick the correct system owner, manager, or resource approver from the approver field.
- Add a clear justification, for example:
Need temporary production access for client incident INC-4821 from 2026-08-05 14:00 to 2026-08-05 18:00. Scope limited to project acme-web-prod. - If your provider supports a direct approval link, copy the request URL and send it to the approver in chat or email.
- Verify it worked: the request detail page now shows the correct approver and a recent
Notification sentevent.
Approval email was not delivered or was filtered as spam
- First, ask the approver to search their inbox and spam/junk folder for the request ID or subject line.
- In the dashboard, open the request activity log and use any available
Resend notificationaction. - If your provider supports alternate notifications, send the direct request link through your normal communication channel.
- If your organization manages email allowlists, ask your admin to allow the sender domain used by the access system.
- If you have admin help available, ask them to check your mail system for bounce or quarantine events for the approver's address.
- Verify it worked: the activity log shows a new notification event and the approver confirms receipt.
Required fields were incomplete
- Open the request and look for
Edit,Complete details, orFix validation errors. - Fill every required field shown on the page, especially:
Business justification Duration or end time Ticket/incident number Resource name Data classification acknowledgement - Use specific text instead of a short note like
Need access. - Good example:
Need read-only access to project billing reports for monthly reconciliation. Related ticket FIN-2038. Access needed until 2026-08-08 17:00 UTC. - If the request cannot be edited, cancel it and submit a new one with all required fields completed.
- Verify it worked: the validation warning disappears and the request status changes from
IncompleteorNeeds infotoPending approvalwith an assigned approver.
Policy requires a different request type or stronger justification
- Read the policy message on the request page carefully. Many systems separate standard access from temporary elevated access.
- Cancel the current request if it is for the wrong access type.
- Re-submit using the correct workflow, such as:
Standard access Temporary elevated access Emergency / break-glass access Read-only access - If the page says MFA (multi-factor authentication, a second sign-in step) is required, complete MFA in your account settings first, then re-submit.
- If the policy requires a ticket number or manager approval before system-owner approval, include that reference in the form.
- Verify it worked: the new request no longer shows the policy rejection banner and enters the correct approval flow.
Expired request
- Open the old request and confirm the status shows
Expiredor similar. - If there is a
Clone,Re-submit, orCreate similar requestaction, use that so you do not have to re-enter everything. - Update the dates and business reason before submitting again.
- If there is no re-submit option, create a fresh request and include a note like:
Re-submission of expired request 10482. Access still required for active client work. - If the original approver was unavailable, choose the correct backup approver if your workflow allows it.
- Verify it worked: the new request has a fresh submission time and is no longer marked expired.
Approver unavailable and no backup/escalation configured
- Contact the assigned approver directly with the request link and request ID.
- If they are out of office, ask your manager, project owner, or service owner who the backup approver should be.
- Cancel and re-submit the request to the backup approver if your process allows that.
- If your organization uses a service desk, open a ticket asking for approver reassignment. Include:
Request ID Resource requested Current approver Reason backup approval is needed Required-by date/time - If you are an admin and your system supports reassignment, reassign the request in the dashboard's request detail page.
- Verify it worked: the request shows a new assigned approver and the activity log records the reassignment.
Prevention
- Add an approval SLA (service-level agreement, expected response time) reminder. In your provider's notification or workflow settings, turn on reminders at 24 and 48 hours, and escalation after 72 hours.
- Require backup approvers for critical resources. In your access policy or resource owner settings, add at least one alternate approver for production systems, finance tools, and shared mailboxes.
- Standardize request templates so required fields are always present. Use a template like:
Access type: Resource: Business justification: Ticket number: Start time: End time: Manager: - Route approval links through more than email. If your system supports it, enable dashboard notifications and chat notifications in addition to email so a spam filter does not stall the request.
- Review stale requests weekly. In your provider's dashboard, filter
Access Requests → Status: Pendingand sort by oldest first; cancel expired requests and reassign anything blocked on unavailable approvers. - Add a pre-submit check for policy fit. Before requesting production or admin access, confirm whether the resource requires standard access, temporary elevation, or emergency access so the first request enters the correct workflow.
This article was written by an AI system and published pending human review. Verify anything you intend to act on.
Have a project in mind?
Get an instant AI price estimate for it, or talk directly to our team.
One email a month on what we learn building with AI