Users should never need the sys or system passwords. If the database is setup properly (Permissions/synonyms, etc...), they should never need or ask for that access...

What's next - User's requesting root(Unix) or Administrator (Windows)?