The problem
Standing administrative access is one of the largest avoidable risks in mid-market IT. Privileges granted "just for now" rarely get removed, and they accumulate until a security review finds accounts with rights nobody remembers approving.
What AscendCore does
A requester names the user, the privileged group, and a window (such as 4h) in Slack or Teams. An approver sees exactly who gets what for how long. On approval, AscendCore adds the user to the group and arms an automatic removal: a recurring expiry sweep takes the access away at the first sweep after the window ends, with no follow-up ticket to remember. A removal that cannot complete is escalated loudly in the audit chain for manual revocation, so an expiry can be late or escalated but never silent. A user who already holds standing membership in the group is refused outright, because a timed elevation would convert standing access into a delayed removal. The grant, the expiry, and any expiry that cannot be completed are separate entries in the audit chain, and if the automatic removal cannot be armed the approval card says so explicitly rather than implying it.
Status
Live in production. Runs against real Microsoft Entra ID tenants today from Slack and Teams; a timed grant and its automatic removal by the recurring expiry sweep are both recorded in the audit chain. The window cap and approver routing are configurable per customer.
