Reference Guide
...
SAPM Mail List Notifications
Password Retrieval Second-Level Approval Notifications
a two level approval can be set up for the desired user groups with a device group realm defined with the device that contains the sapm account these user groups should have a sapm second level approval requirement function group defined in their portal functions realm to do so, follow these steps navigate to policy control > portal functions set the realm between the sapm second level approval requirement function group and the user group of the user that will need the second level approval when a user who requires two level approval attempts to retrieve an sapm password, a sapm password approval request email is sent to the list below user groups with the single connect sapm admin and the single connect sapm network admin portal functions single connect sapm admin grants rights to manage all sapm accounts and view all logs single connect sapm network admin grants rights to manage and view all accounts of devices defined to the user in device group realms user groups with the full control permission over the sapm account that requested the approval to set up managerial approval for sapm password retrieval navigate to policy control > portal functions set the realm between the sapm admin function group and the user group of the user that will be able to provide first approval for all password retrieval requests and/or set the realm between the sapm network admin function group and the user group of the user that will be able to provide first approval for all password retrieval requests related to the devices in their device group realms only if a user from these lists approves the initial request, a sapm password approval request email is sent to the second level approvers, who are user groups with the single connect sapm secondlevel admin and single connect sapm secondlevel network admin portal functions single connect sapm secondlevel admin grants rights to give second level approval for all sapm accounts and view all logs single connect sapm secondlevel network admin grants rights to give second level approval for all accounts of devices defined to the user device group realms to set up two level managerial approval for sapm password retrieval navigate to policy control > portal functions set the realm between the sapm second level admin function group and the user group of the user that will be able to provide second approval for all password retrieval requests and/or set the realm between the sapm network admin function group and the user group of the user will be able to provide second level approval for all password retrieval requests related to the devices in their device group realms only if a user from these lists approves the second level request, the requester receives an email and can proceed to password checkout if any of the authorizers deny the request, informational emails are sent to all participants, and the request is terminated