Skip to content

Configuring Approval Processes for Agent Requests

As an administrator, you can configure approval processes for requests to activate and deactivate agents.

Configuring the Approval Process for Requests to Activate Agents

You can define the approval process for requests for activating agents at the global level.

  1. In Identity Security Cloud, go to Admin > Global > System Settings.

  2. From the left panel, select Feature Settings > Approval Settings.

  3. Select the Agent Requests tab.

  4. In the Requests to Activate Agents section, select the Requires Approval toggle.

  5. Configure the approval policy:

    • In the Approvers section, choose whether the request will be reviewed by a single approver or multiple approvers:

      • Single Approver

        • Select Single from the Approval Type field.

        • Select the type of reviewer from the Reviewer Category field. You can select from the following options:

          • Source Owner - The source owner reviews the request.
          • Governance Group - The selected governance group reviews the request. Only one identity in the governance group is required to approve the request.
          • Primary Owner - The primary owner of the agent reviews the request.
          • Additional Owners - Any of the agent’s other owners can review the request.
          • Requester's Manager - The manager of the user who submitted the request reviews the request.
          • Identity - The selected identity reviews the request.
          • All Owners - The primary owner and additional owners review the request. Only needs to be approved or denied by one.
      • Multiple Approvers

        • Select Multi-Step from the Approval Type field.

        • In the Reviewers section, select Add Reviewer.

        • Configure the approval policy by taking the following actions:

          • Select the types of reviewers from the Reviewer Category field. You can select from the following options:

            • Source Owner - The source owner reviews the request. This is the default reviewer.
            • Governance Group - The selected governance group reviews the request. Only one identity in the governance group is required to approve the request.
            • Primary Owner - The primary owner of the agent reviews the request.
            • Additional Owners - Any of the agent’s other owners can review the request. Only needs to be approved or denied by one.
            • Requester's Manager - The manager of the user who submitted the request reviews the request.
            • Identity - The selected identity reviews the request.
            • All Owners - The primary owner and additional owners review the request. Only needs to be approved or denied by one.
          • Add additional reviewers by selecting Add Approver.

          • Remove reviewers by selecting the Delete icon .

          • Move a reviewer’s tile to change the order the approvers will review the request.

            Note

            All reviewers must approve the request for the agent to be activated. If one reviewer denies the user’s request, the request is denied.

          • Select Save to save the approval process.

            If the approval process requires changes, select Edit Approvers. You can add or remove approvers and rearrange the order in which they will review the request.

  6. Choose whether comments are required when reviewers approve or deny requests to activate agents.

  7. Select Save at the bottom of the page to save these approval settings.

From this page, you can also define the approval process for requests to deactivate agents, set up reminders for approvers, and configure an escalation process. For more information about reminders and escalations, refer to Setting Global Reminders and Escalation Policies.

Configuring the Approval Process for Requests to Deactivate Agents

You can define the approval process for requests for deactivating agents at the global level.

  1. In Identity Security Cloud, go to Admin > Global > System Settings.

  2. From the left panel, select Feature Settings > Approval Settings.

  3. Select the Agent Requests tab.

  4. In the Requests to Deactivate Agents section, select the Requires Approval toggle.

  5. Configure the approval policy:

    • In the Approvers section, choose whether the request will be reviewed by a single approver or multiple approvers:

      • Single Approver

        • Select Single from the Approval Type field.

        • Select the type of reviewer from the Reviewer Category field. You can select from the following options:

          • Source Owner - The source owner reviews the request.
          • Governance Group - The selected governance group reviews the request. Only one identity in the governance group is required to approve the request.
          • Primary Owner - The primary owner of the agent reviews the request.
          • Additional Owners - Any of the agent’s other owners can review the request.
          • Requester's Manager - The manager of the user who submitted the request reviews the request.
          • Identity - The selected identity reviews the request.
          • All Owners - The primary owner and additional owners review the request. Only needs to be approved or denied by one.
      • Multiple Approvers

        • Select Multi-Step from the Approval Type field.

        • In the Reviewers section, select Add Reviewer.

        • Configure the approval policy by taking the following actions:

          • Select the types of reviewers from the Reviewer Category field. You can select from the following options:

            • Source Owner - The source owner reviews the request. This is the default reviewer.
            • Governance Group - The selected governance group reviews the request. Only one identity in the governance group is required to approve the request.
            • Primary Owner - The primary owner of the agent reviews the request.
            • Additional Owners - Any of the agent’s other owners can review the request. Only needs to be approved or denied by one.
            • Requester's Manager - The manager of the user who submitted the request reviews the request.
            • Identity - The selected identity reviews the request.
            • All Owners - The primary owner and additional owners review the request. Only needs to be approved or denied by one.
          • Add additional reviewers by selecting Add Approver.

          • Remove reviewers by selecting the Delete icon .

          • Move a reviewer’s tile to change the order the approvers will review the request.

            Note

            All reviewers must approve the request for the agent to be deactivated. If one reviewer denies the user’s request, the request is denied.

          • Select Save to save the approval process.

            If the approval process requires changes, select Edit Approvers. You can add or remove approvers and rearrange the order in which they will review the request.

  6. Choose whether comments are required when reviewers approve or deny requests to deactivate agents.

  7. Select Save at the bottom of the page to save these approval settings.

From this page, you can also define the approval process for requests to deactivate agents, set up reminders for approvers, and configure an escalation process. For more information about reminders and escalations, refer to Setting Global Reminders and Escalation Policies.

Documentation Feedback

Feedback is provided as an informational resource only and does not form part of SailPoint’s official product documentation. SailPoint does not warrant or make any guarantees about the feedback (including without limitation as to its accuracy, relevance, or reliability). All feedback is subject to the terms set forth at https://developer.sailpoint.com/discuss/tos.