State of IAM Survey

Free Demo Contact
What is Self-Service? IT Self-Service Portal

What is Self-Service? IT Self-Service Portal

Self-service is a form of service delivery in which users submit requests, make changes, and complete tasks as independently as possible. The concept spans everything from online banking to booking systems. In a business context, it is becoming the default expectation. A 2024 Forrester report found that 81% of enterprises are making a significant shift toward self-service models, driven by pressure to reduce support costs and improve response times.

In IT, self-service covers two distinct models that are often treated as the same thing. Understanding the difference matters, because they serve different users and require different tooling.

Two Types of Self-Service in Organisations

User Self-Service

Manager Self-Service

Who uses it

Individual employees

Team leaders and managers

Purpose

Handle personal IT requests independently

Arrange matters for their own team members

Examples

Request a licence, reset a password, access a project mailbox

Assign access rights, manage leave, schedule training, arrange IT resources

Portal type

Employee self-service portal

Manager administration portal

User Self-Service

User self-service gives employees direct control over a defined range of tasks through a self-service portal. In most organisations this starts during onboarding, when employees gain access to an employee portal to view payslips, book leave, and update personal details. In workforce planning, employees increasingly have self-scheduling options. Within IAM, user self-service extends to requesting additional licences and access rights without needing to contact IT directly.

Manager Self-Service

Manager self-service is the indirect equivalent, designed for team leaders who need to arrange things on behalf of their employees. This covers HR tasks such as absence and leave management, but also scheduling staff for training, arranging additional IT resources, and managing access rights for their team. Rather than routing these requests through IT support, managers handle them directly through a dedicated administration portal.

Benefits of Self-Service

Self-service delivers measurable benefits across the organisation, though the nature of those benefits depends on who you are asking.

For employees, the most immediate benefit is a better experience. Waiting for IT to action a straightforward request, or navigating complex procedures that depend on someone else's availability, creates friction. Self-service removes that dependency. Employees handle what they need, when they need it, from wherever they are working.

For managers, self-service is not just about efficiency. Having direct control over administrative tasks for your team makes you more actively engaged with the information. Absence figures and licence usage are visible to any manager, but when you can act on them directly the data becomes something you engage with rather than simply observe.

For the organisation, self-service improves efficiency, scalability, and compliance at the same time. Because self-service requires processes to be standardised and automated before they can be delegated, it drives better process design as a side effect. That standardisation directly supports compliance with UK GDPR, ISO 27001, and other frameworks that require consistent, traceable access decisions.

Self-Service in Identity and Access Management

Account and access management is one of the most time-consuming areas in IT operations. In an organisation with hundreds or thousands of employees and dozens of applications, the administrative load compounds quickly.

Part of what makes this complex is the permissions structure within individual business applications. An Electronic Patient Record (EPR) system must be configured so that every clinician can perform only the actions they are qualified for, and only for the patients and departments they are responsible for. An Enterprise Resource Planning (ERP) platform carries similarly granular permissions, as does a local authority case management system. When employees regularly change role or department, when new starters join every week, and when individuals need access to a project mailbox or an additional licence, a significant part of each working day can disappear into account and permissions changes.

A modern IAM solution such as HelloID addresses this in two ways.

The 80/20 split in IAM: Automated provisioning handles approximately 80% of all account and access management tasks. The remaining 20% of ad hoc requests are where self-service makes the difference.

The 80% is handled through automated provisioning using Role-Based or Attribute-Based Access Control (RBAC or ABAC). Business rules ensure that, depending on a person's role, department, location, and other attributes, the correct accounts and permissions are granted automatically through the HelloID Provisioning module.

The remaining 20% covers access rights that cannot be derived directly from a role. A business analyst who needs a specific design tool for one project. An employee taking on an additional responsibility who needs access to a project share or group mailbox. These individual, ad hoc requests are where self-service steps in.

Self-Service in HelloID

Within HelloID, the Service Automation module delivers IAM self-service through two mechanisms.

Delegation of IT Tasks

Most account and permissions changes ultimately need to be implemented in back-end systems such as Active Directory or Entra ID. These are complex environments, which is why changes are typically handled by second-line administrators.

Service Automation changes that by delegating those tasks to first-line support staff, managers, and key users: trusted individuals within a specific department who have been granted the ability to carry out defined administrative tasks on behalf of that area. Delegation works through configurable forms. The person making the change enters the relevant details and confirms, and Service Automation executes the change correctly in the underlying system. The delegated user never touches the back-end directly; they interact only with the form. This keeps the process secure while removing the bottleneck from second-line IT.

Self-Service Portal

For end users, Service Automation also supports direct self-service through a configurable portal. Employees can request IT resources when they need them: a specific application, a new mailbox, additional storage, or a password reset. Requests are not executed automatically. HelloID routes each one through a configurable approval workflow, sending it to the right people before any access is granted. The system can also verify whether the requester meets defined criteria before the request progresses.

The result is self-service at two levels: end-user self-service for individual requests, and manager self-service for team-level administration. Both operate within controlled, auditable workflows.

What is the difference between user self-service and manager self-service?

User self-service lets individual employees handle their own requests, such as requesting a licence, resetting a password, or accessing a shared mailbox. Manager self-service gives team leaders the ability to arrange things directly for their staff, such as assigning access rights, managing leave, or scheduling training. Both run through the same underlying platform but serve different roles and use different interfaces.

Is IT self-service secure?

Yes, when implemented correctly. Self-service in an IAM platform such as HelloID does not give users direct access to back-end systems. Every request passes through a configurable approval workflow, and delegated tasks are executed through controlled forms rather than direct system changes. Every action is logged automatically, making self-service both secure and fully auditable.

What is a key user in the context of self-service?

A key user is a trusted individual within a specific department or team who has been granted the ability to carry out defined IT administration tasks for that area. Rather than every request going to second-line IT, the key user handles routine access changes locally, within a controlled, delegated workflow. This reduces helpdesk load without compromising security or auditability.

How does self-service support compliance?

Structuring requests into automated workflows means every action is logged, consistent, and traceable. That audit trail supports compliance with UK GDPR, ISO 27001, and other frameworks requiring demonstrable control over who has access to what and how those decisions were made. Self-service also prevents ad hoc, undocumented access changes that create compliance gaps.

Can the self-service portal be configured to match our processes?

Yes. In HelloID, both the self-service portal and the delegation forms are fully configurable. Organisations define which resources are requestable, who must approve each type of request, what criteria the requester must meet, and whether time limits apply to any granted access. The platform adapts to your processes, not the other way around.