The change request that arrived by text.

The scenario:

“Quick one, while you’re in there, add Sarah to the finance group.” It came by text, mid-migration, from the office manager. 

Six weeks later Sarah forwards a payment email she should never have seen, and nobody remembers who approved her access. Informal change requests feel like good service right up until one becomes an incident with your name on it. 

The insurance angle makes this concrete. Cyber policies now ask who is authorized to request access changes and how requests are verified. An access change granted from an unverified text message is the gap an assessor, or an attacker, looks for. The single door is not bureaucracy. It is the evidence trail protecting you when something breaks. 

The prompt:

You are building a change request intake standard for an MSP. 

Context: [how changes arrive today, your PSA or ticketing tool, one informal change that later caused pain] 

Build: 

  • The single-door rule: every change lands in the queue, whatever channel it arrived by, and who is responsible for logging it 


  • A 60-second intake template: what, who requested, authority check, risk note, rollback 


  • The authority matrix per client: who is allowed to request access changes, financial system changes, new starters 


  • The polite deflection script for changes requested by text, in person, or mid-job 

Make logging faster than not logging, or nobody will do it.