I'm a Windows Admin so those that integrate with Windows will likely be most helpful. My main challenge at this point is just with file shares but as SharePoint use increases it will only make this harder.
I've got all my directories setup and many security groups that are setup with the policy of least access needed is allowed. My problem is tracking it all for HR and compliance reasons.
User A needs permission to resource 1. He needs to get approval from the manager of resource 1 and then the manager of the managers needs to approve this access as well. Once all of that is done I can make the change. At this point we're just tracking it on paper but it's such a burden and likely to fall out of compliance when user A is re-assigned and no longer should have access to resource 1 among other scenarios.
I know what I'm looking for should already exist but I haven't known where to look and I'm reaching out to the community.
EDIT:
Thanks for the responses. I think they touch on the technical side and hopefully my question isn't off-topic. I should have made myself clearer on my goal. What systems do you use to show an auditor that on X date user A had permission added/removed and it was approved by manager Y? I have a basic ticketing system in place currently but I don't see it delivering what I need in an easy to understand format.
In my mind I'm picturing something that would have a report on user A that would show all the changes that had been made to their permissions. Ideally something linking to Active Directory would be ideal but at this point I'm hoping to find something more basic. I'm hoping that there is an application specifically for this. I feel like this must be a requirement for larger enterprises and such software exists.
Thanks!