@@ -269,7 +269,7 @@ Being a maintainer gives you access to much more than just the ability to merge.
### Granting others maintain access
Do not grant people maintainer access without an [Access Request](/handbook/security/corporate/end-user-services/access-requests/access-requests/). As a maintainer you have the ability to grant others maintainer access. Don't do so without following the Access Request process to garner the appropriate approvals and create the necessary documentation.
Do not grant people maintainer access without an [Access Request](/handbook/eta/corporate-it/end-user-services/access-requests/access-requests/). As a maintainer you have the ability to grant others maintainer access. Don't do so without following the Access Request process to garner the appropriate approvals and create the necessary documentation.
### Description Templates for Issues and Merge Requests
@@ -7,7 +7,7 @@ description: Finance Systems Access Requests
Many finance systems that are provisioned are also considered a SOX system and are subject to the [SOX Program.](https://internal.gitlab.com/handbook/internal-audit/sarbanes-oxley/)
The finance systems admin team goes through additional procedures when handling [Access Requests.](/handbook/security/corporate/end-user-services/access-requests/access-requests/)
The finance systems admin team goes through additional procedures when handling [Access Requests.](/handbook/eta/corporate-it/end-user-services/access-requests/access-requests/)
This applies to the following systems:
@@ -22,12 +22,12 @@ This applies to the following systems:
### Additional Procedures
On top of the [GitLab Access Request](/handbook/security/corporate/end-user-services/access-requests/#individual-or-bulk-access-request) process, the team will perform the following:
On top of the [GitLab Access Request](/handbook/eta/corporate-it/end-user-services/access-requests/#individual-or-bulk-access-request) process, the team will perform the following:
- Ensure/Clarify access being requested is specific to the system being requested.
- Example: Instead of `Needs read only access to Netsuite`, the team will clarify with the requester that they are asking for the `Custom Auditor (read only)` role in Netsuite.
- See matrix [here](/handbook/business-technology/enterprise-applications/finsys-access-requests/#-system-specific-access-request-requirements) for System specific requirements.
- Seek Business Owner's approval of the exact role and/or permission being requested, according to who is listed in the [Tech Stack.](https://gitlab.com/gitlab-com/www-gitlab-com/-/blob/master/data/tech_stack.yml) This includes [baseline entitlement(s).](https://internal.gitlab.com/handbook/security/corporate/end-user-services/access-request/baseline-entitlements/)
- Seek Business Owner's approval of the exact role and/or permission being requested, according to who is listed in the [Tech Stack.](https://gitlab.com/gitlab-com/www-gitlab-com/-/blob/master/data/tech_stack.yml) This includes [baseline entitlement(s).](https://internal.gitlab.com/handbook/eta/corporate-it/end-user-services/access-request/baseline-entitlements/)
- Once approved, the team will provision the user in the system and add to the corresponding Okta Google group (if necessary).
- Once provisioned, the team will take a screenshot of the user record in the system with a timestamp and attach it to the issue and then close.
@@ -152,7 +152,7 @@ As part of this process, the Business Owner must collaborate with Legal and IT C
### Access Requests
Please review our [Access Requests handbook page](/handbook/security/corporate/end-user-services/access-requests/access-requests/) to find more information on how to request access to systems. Choose the right template for your use case and follow the instructions.
Please review our [Access Requests handbook page](/handbook/eta/corporate-it/end-user-services/access-requests/access-requests/) to find more information on how to request access to systems. Choose the right template for your use case and follow the instructions.