Prerequisites
To enable the ability to request on behalf in an organization, admins must enable the Global requestor role in Organization Settings > Access Requests.
Multiple request configurations
The following table applies to resources and groups which have one or more request configurations applied. Request configuration are applied after visibility checks. If your resources and groups have limited visibility, first apply visibility rules, then the request configurations tables.
For example, the first With group -> Not requestable row means if requester R is a member of group G, and the configuration disallows requests from members of group G, requester R can still request on behalf of user B, because user B is not a member of group G.
Visibility rules
The following table applies groups and resources which have limited visibility settings applied.
If the target user cannot view the requested item, but the request is created, they cannot see the item until the request is approved—creating the request does not escalate view privileges.