NEWFreshservice is now a Ploy integrationSee what shipped
1.0ACCESS REQUESTS

Make just-in-time access the default.

Employees ask for access in the tools they already have open, and policy clears the routine requests on its own. Exceptions reach a reviewer with the context already gathered, then Luna grants the access and removes it when the approved window ends.

Less waiting for employees. Less manual work for IT. Less standing access for security.

SlackTeamsPortalBrowser extensionCLIMCPAI agents

Ploy· Direct message
Message Ploy
Figma · EditorUNTIL FRIDAYREQUESTED09:41
Asked in SlackFIGMA · EDITOR · UNTIL FRIDAY
POLICY CHECKED09:41
Design team
MFA enabled
Duration ≤ 7 days
Luna analysing risk
AUTO-APPROVEDPOLICY MATCHEDRoutine requests that match policy skip approval automatically.
PROVISIONED09:42
Granted in FigmaROLE · EDITOR
EXPIRESFRI 18:00
Figma · EditorMaya Osei · maya.osei@company.comGRANTED
Expires Friday at 18:00Revocation scheduled
EXPIRY SCHEDULED · FRIDAY, 18:00ACCESS REMOVED AUTOMATICALLY
1.1REQUEST

Request access wherever work starts.

Ask in Slack or Teams, choose from the portal, use the browser extension, send a request through the CLI or MCP, or let an agent request access. Every route enters the same governed flow.

  • Slack
  • Teams
  • Portal
  • Browser extension
  • CLI
  • MCP
  • AI agents
Jon Adeyemi asks for Entra ID · Global Administrator4 hours · as jon.adeyemi@admin.company.com
ALREADY HOLDS
Entra ID · USER
GitHub · repo:read
PRIOR REQUESTS
3 approved
0 rejected
TEAM ADOPTION
2 of 9UNCOMMON
LUNA'S READ
“Two of nine teammates hold this role, both platform engineers. Jon’s last three requests were scoped to read access. A 4 hour window is proportionate if the change he described needs it.”
ApproveRejectREASON REQUIRED
Maya Osei asks for Figma · Member1 month · as maya.osei@company.com
ALREADY HOLDS
Figma · VIEWER
Miro · Member
PRIOR REQUESTS
5 approved
0 rejected
TEAM ADOPTION
7 of 9COMMON
LUNA'S READ
“Seven of nine designers hold Member, and Maya has been on a viewer seat daily for six weeks. This is the team’s standard grant; a month matches how the team holds it.”
ApproveRejectREASON REQUIRED
Tom Ligeti asks for AWS · AdministratorAccessIndefinite · as tom.ligeti@company.com
ALREADY HOLDS
AWS · ReadOnlyAccess
Datadog · Standard
PRIOR REQUESTS
1 approved
1 rejected
TEAM ADOPTION
1 of 12RARE
LUNA'S READ
“One person on the team holds account-wide admin, and the request is indefinite. The deploy task Tom described needs write access to one service — a scoped role with an expiry would cover it.”
ApproveRejectREASON REQUIRED

One request card, one policy engine

A request from Slack, the portal, the CLI or an agent becomes the same request card, carries the same evidence, and is evaluated by the same central policy engine. The channel changes; the governance does not.

Jon Adeyemi09:14Morning — I need Metabase for tomorrow’s board prep
PloyAGENT09:14Analysing…PloyAGENT09:14Sure — which workspace, Finance or Growth?
Jon Adeyemi09:15finance please
PloyAGENT09:15Analysing…PloyAGENT09:15Done — Finance viewer until Friday. It’s live now.
BIUS
Message Ploy
+Aa@

Ask in plain language

Describe what you need and why. Luna gathers only the missing details before submitting the request.

Entra ID · Global AdministratorNEEDS APPROVAL
WHICH ACCOUNT GETS THE GRANT
jon.adeyemi@admin.company.comDOES NOT HOLD THIS ACCESS · DEFAULT
jon.adeyemi@company.comNORMAL ACCOUNT
4 HOURS1 DAY7 DAYSClamped to the policy window

The right identity and account

Ploy confirms who the access is for and which account should receive it.

Figma · Member
REQUEST FOR
Design Team (14 people)

Request for yourself or a team

One request can cover an individual, a group of people or a defined team.

Awaiting approvalRequest sent today
JMWaiting on Jess Mertens
Nudge reviewers
Reviewers nudged

Know exactly what is happening

See who the request is waiting on, what happens next and when the approved access will expire.

1.2ONE REQUEST, TWO ROUTES

Fast enough to request only when it is needed.

Ploy completes the whole loop quickly enough for temporary access to become practical for everyday work. Scroll one request through the portal, for yourself and on behalf of someone else.

Request access
Recipient:JAJon Adeyemi(Myself)PRPriya Raman(On behalf)
Browse the catalog
Select the resources you’d like to gain access to
Search catalog items…
CatalogAll catalogsCatalog itemAll items
Salesforce · Sales user
Revenue · Salesforce
Add
Atlassian Basic Licence
Core Productivity Apps · Atlassian
Added
ChatGPT Team seat
AI tools · OpenAI
Add
Figma · Editor
Design · Figma
Add
GitHub · Engineering org
Engineering · GitHub
Add
Zoom · Large meetings
Core Productivity Apps · Zoom
You have access
JAJon Adeyemi(Myself)
ResourceStatusDuration
/Atlassian Basic Licence Auto-approve 3 months
PRPriya Raman(On behalf)
/Atlassian Basic LicenceNeeds approval 3 months
Access duration
Applied to every item in this request
4 hours1 day1 week1 month3 monthsCustomIndefinite
Add context for the approver (optional)
Customise individual resources
CancelSend Request
1.3POLICY

Routine requests do not need a reviewer.

The evergreen policy engine checks who is asking, what they need, the conditions around the request and how long the access may last. Safe requests approve automatically. Disallowed access is blocked. Only the exceptions go to a person.

Access policy · Snowflake ANALYST
WHEN
Access is requested
DepartmentisData
Employment typeisFull time
MFAisEnabled
THEN AUTO-APPROVEMAX 8 HOURS
WHAT THE EMPLOYEE SEES
Snowflake · ANALYSTAUTO-APPROVE
Entra ID · GLOBAL ADMINISTRATORNEEDS APPROVAL
Production DB · OWNERWON'T BE SENT

One policy system

The same policies that govern lifecycle changes, reviews and remediation decide requests too, reading department, employment type, MFA, access sensitivity and other context to route each one.

REQUESTED · 14 DAYS
POLICY MAX · 8 HOURS
ApproveRejectGRANTED · MAX 8 HOURS

Policy limits every grant

A requester or approver cannot extend access beyond the maximum duration the policy allows.

HUMANAGENT

Every requester follows the same rules

Employees, service accounts, machines and agents enter the same governed decision process.

ACCESS GRANTS
Snowflake · ACCOUNTADMINMAR 2024INDEFINITE
GitHub · adminJUN 2024OUTSIDE POLICY
Figma · EditorNOV 2023PREDATES POLICY

Existing grants come under the same rules

Access already in place can be compared with current policy, duration and ownership requirements.

1.4APPROVALS

Reviewers decide with context, not investigation.

When human judgement is needed, Ploy gathers the evidence before asking for a decision. One ask, Tom's, walked through what the reviewer actually sees.

THE REQUESTER
TLTom LigetiPlatform team · as tom.ligeti@company.com
PRIOR · 1 APPROVEDPRIOR · 1 REJECTEDROUTES TO · PLATFORM LEADS, ROTATING

Less waiting. Less administration. Less standing access.

Employees get the access while it is still useful to them. Reviewers decide with the context already gathered, and Luna removes the grant when the approved window ends, every time. Because access is quick to get and reliable to remove, far less of it needs to be permanent.

Avantia Law
Ploy has transformed how we do access requests & we wouldn't be able to go back to the way it was.
Peter F.Head of IT & Infosec, Avantia Law
Read the story
Liberis
Ploy has enabled us to completely automate employee onboarding and offboarding, saving us 150 manual actions, clicks, and hours of time per employee.
Paul HartHead of IT, Liberis
Welcome to the Jungle
With Ploy, we've turned a tedious weekly task into easy automated flows. We're saving half a day a week and have completely streamlined onboarding across all our SaaS tools. Total game changer.
Devon BrownSenior IT Engineer, Welcome to the Jungle
Luno
Ploy saved me from drowning in spreadsheets, manual licence assignment and SaaS sprawl. It lets us easily make sense of what's being bought, used, and wasted which is more than I can say for most software tools. The best part? They listen, iterate fast, and don't take themselves too seriously. Perfect match.
Simon FishleyGlobal IT Director, Luno
Read the story

Access when it is needed. Gone when it is not.

Make just-in-time access practical across every app, group and resource. Ploy handles the request, decision, provisioning and removal as one continuous flow.