Investigate a denied request
Find the failed access check before changing a policy.
Read the denial reason
Find the request in activity and confirm its identity, connection, tool, resource, and time. A denial can come from a mandatory access check independently of the write setting.
Correct the failed condition
Keep the original request context when verifying the correction.
- Membership or team: check the authoritative group and connection scope.
- Credential: complete the affected identity’s provider authorization.
- Tool or resource: use an active reviewed tool within its allowed boundary.
- Policy: check Default access, Write decision, stricter team rules, and any content evaluation result.
Troubleshooting
Allow reviewed writes did not fix it
That setting does not restore revoked membership, enable an installation, or permit an unknown resource. Use the recorded reason to find the actual blocker.
It works for an administrator but not the member
Repeat the check as the affected member. Compare their team scope, personal provider authorization, and permitted resource.
Frequently asked questions
Can an administrator approve a denied request?
An exact approval cannot override a failed access check. Resolve the denial first; approval applies only when the resulting decision requires it.