Occasionally we get attackers sending team member access requests.
How do we disable the mechanism for requesting access? I want to ensure that no user accidentally approves a request from a look-alike phishing domain or similar. We only want to add employee access manually.
I know that each admin can turn off notifications individually, but we don't want another thing to audit. This also doesn't appear to help with eg., the Slack integration.