Account Base Approval Mechanism
The approval mechanism is activated for each account and sub-account under the group. Different manager user groups can be assigned for account approvals. Approvals can be made through the Kron PAM GUI, by email, or through the Kron PAM mobile application. All users, except the SAPM Admin user, are forced to run through the approval mechanism. Even if a user group has permission for an account or group, it must first get approval. Creator users also need to get approval for their accounts. In the SAPM Tree structure, approval for sub-accounts can be obtained from any parent group on the tree.
If there are differences in approval levels, a multi-level approval structure can be activated. In this way, more authorized managers can approve a higher level.
In addition, escalation can be provided for the manager at each level. If the managers at that level do not take any action, the approval request is added to the escalated managers.
The following parameter is defined in the System Config Manager to activate the approval mechanism:
Parameter Name | Parameter Value | Description |
sapm.approval.workflow | AccountBasedManager | The parameter defined to activate the approval mechanism. |
sapm.account.manager.level.count | 3 (Default is 2) | Passes the approval structure to the multi-level structure. |