Setting Global Reminder, Escalation, and Timeout Policies
If an assigned approver has not taken action on a request, you need the ability to automatically remind them that their review is required. If too much time passes, you need to be able to escalate the issue by sending the request to another reviewer.
You can set and update the settings for these reminders and escalations, define the identity who will act as the fallback approver, configure the length of time to wait between escalations, and set how often to send reminders to reviewers. You can also set the number of days before a request times out, or expires.
Changes to the reminder, escalation, and timeout configurations will only affect access requests created after the change is made. Pending requests will follow the configuration that existed at the time the request was submitted.
Note
By default, requests time out when there is no action for 90 days. No reminders or escalations take place after that time.
Configuring Approval Settings
You can configure global approval settings for requests in Identity Security Cloud. In addition to global requests, you can configure specific settings for access requests and for entitlement descriptions.
If you choose not to configure access requests or entitlement descriptions but you do configure global timeouts, reminders, and escalations, your global configuration will be applied to those approvals as well.
Any settings that you configure for individual access items will override the global settings for that item. For details on configuring approval timeouts, reminders, and escalations for individual access items, refer to Configuring Roles for Requests, Configuring Access Profiles for Requests, and Configuring Individual Entitlement Access Requests.
Workflows also override any global settings. Refer to Workflows.
To configure global approval settings:
- Go to Admin > Global > System Settings.
- From the left navigation, select Feature Settings > Approval Settings.
- Select the tab you want to add or update settings for: Global, Access Requests, Entitlement Descriptions, or Agent Requests.
- In the Timeout field, select the number of days you want to allow before requests expire. 90 days is the maximum.
-
In the Reminders section, select the toggle if you want to enable reminders, then complete the following fields:
- Number of Reminders - Maximum number of reminders that will be sent.
- Days After the Request to Start Reminders - Number of days after an approval request is initiated before you want the first reminder to be sent.
- Reminder Frequency - How often reminders will be sent. Options include daily, weekly, or monthly.
- Times - Time of day the reminders will be sent.
- Schedule Preview - Review the schedule of when reminders will be sent. If adjustments are needed, make changes to the prior fields and recheck the schedule preview.
Note
Time zone is configured at the bottom of the page.
-
In the Escalations section, select the toggle if you want to enable escalations, then complete the following fields:
- Days After the Request to Start Escalation - Number of days after an approval request is initiated before you want the first escalation to take place.
- Escalation Frequency - The timing of approval escalations. Options include daily, weekly, or monthly.
- Times - Time of day the escalation will take place.
- Reviewers - Select Edit Approvers to open the Escalation Chain interaction.
- Make changes to the Reviewer Category or select Add Approver. Available options include Manager, Identity, Governance Group, or Owners.
- When you add an approver in the Identity or Governance Group category, a field appears where you can select which one.
- Select Save.
- To reorder approvers, select Edit Approvers, then select the reorder icon
next to an approver to click and drag. Select Save.
- Fallback Approver - Select a Reviewer Category. When you add an approver in the Identity or Governance Group category, a field appears where you can select which one. A request is sent to a fallback approver when it has been routed through the full Approvers escalation chain and no one has taken action on it. Refer to Escalation Pattern.
- Schedule Preview - Review the schedule on which reminders will be sent. If adjustments are needed, make changes to the prior fields and recheck the schedule preview.
-
Set the Time Zone that will apply to all escalations and reminders.
- Select Save.
Escalation Pattern
If reviewers fail to complete their reviews within the configured time frame and you have enabled escalations, the request is automatically escalated to a new reviewer.
If you have not configured custom approval settings, then the first two times a request is escalated it is sent to the manager of the assigned reviewer. The third escalation is sent to a fallback approver.
The fallback approver is the individual designated to complete the request if the previous reviewers fail to meet the deadline. If an approver is not found during escalation, the request is assigned to the fallback approver. If the fallback approver has been deleted from the system, the request remains with the last valid approver.
Notes
- If the fallback approver is the same identity that submitted the access request, the original requester might be permitted to review their own access request.
- The request will be assigned to the specified identity, even if the identity is disabled or incomplete. In these cases, an admin can reassign the request by submitting an API call with the Forward Access Request endpoint.
- In the case of governance groups, the request will be escalated to each member's manager. If a member does not have a manager to escalate to, the approval will remain with that member while other members' assignments are escalated to their managers. If none of the members has a manager, all members' requests will be escalated to the fallback approver. Likewise, when the escalation has finished all configured
manager_oflevels and reaches the fallback approver stage, all members' requests will be escalated to the fallback approver.
If a reviewer reassigns a request, the timing of the escalation process does not restart. Emails will still be sent out at the designated times.
Email Templates
You can customize the emails that users see when requesting, reviewing, or reassigning access requests using the following email templates:
- Access Request Decision
- Access Request Decision for Others
- Access Request for Other
- Access Request Reassignment
- Access Request Reviewer
- Access Request Sunset Date Reminder
Documentation Feedback
Feedback is provided as an informational resource only and does not form part of SailPoint’s official product documentation. SailPoint does not warrant or make any guarantees about the feedback (including without limitation as to its accuracy, relevance, or reliability). All feedback is subject to the terms set forth at https://developer.sailpoint.com/discuss/tos.