Defines who at a client organization may make IT requests of ITNS — and what each of them is allowed to ask for. This is the list we check before acting on a request.