---
title: Approval Workflow
slug: kronpam-reference-guide-3-5-0/approval-workflow
description: Learn how to utilize the Managerial Approval and Approval Workflow features in Kron PAM to customize and enhance authentication and authorization processes. This document provides detailed instructions on configuring one-level or multiple-level approval m
docTags: 
createdAt: 2022-07-27T11:29:46.000Z
---

The Managerial Approval feature can also be managed by creating workflows so that the authentication and authorization processes are fully customized in terms of approval management. The Approval Workflow is available for Managerial Approval of Connections and Commands. The implementation of an approval workflow for connections and/or commands leads to a fully customized and flexible environment to manage the authentication process.

These Managerial Approval features allow the configuration of a one-level approval mechanism by default, with the user group manager as the managing authority. Additional and increasing levels of managerial approval can be added, in which case, the approval authority can now be assigned for each level - the approval authority can be a user group manager, members of a user group, or any external email address or phone number, which are not required to be defined in the Kron PAM instance.

The Approval Workflow feature can be managed as a policy and used in a policy realm so that the designed workflow can be applied to device realms to flexibly control each user group’s authentication and authorization processes for each device group.

To configure the Approval Workflow:

1. Navigate to **Policy**>**Approval Workflow.**

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/yBrhOkSjEr65rtE8B0nza_image.png "Approval Workflow Tab")

- Define a name for **Workflow** Info and description then click on the **Next** to define workflow levels after clicking add button. (Select the Disable instant approval checkbox if you want to disable instant approval.)

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/4fbi_bySnigw-7SHdyMlX_image.png)

- Configure the level details in the levels step, select the authority and approval tool, and click **Save.**

![](https://api.archbee.com/api/optimize/g9cApVza9NIhSh0pjZYtA/XDRA62z3io1K2IJcoPBRr_image.png)

- After adding one level to the workflow, you can save the workflow or add more levels by using the click of the + plus Level button.

:::hint{type="info"}
If a workflow level is deleted, the new workflow will only be used for new reservation requests. For older created requests the previously created workflow levels are used.
:::

**Hints for the Approval Workflow Configuration**:

- The **Authority** field in the Add Level window includes two options:

o   Th&#x65;**&#x20;Escalate to Group Manager** option allows the manager of the selected group to respond to the approval request.

o   Th&#x65;**&#x20;Escalate to Group** option allows one of the selected group members to respond to the approval request.

o   *The **AD Line Manager** option allows the requester’s Active Directory manager to respond to the approval request.*

o   *The&#x20;****Extra Notification****&#x20;checkbox allows information about approval notifications to be sent to the selected user groups.*

o   *The&#x20;****Select User Group for Approver****&#x20;option allows you to send approval notifications to other approvers only.*

o   *The&#x20;****Select User Group for Requester****&#x20;option allows you to send approval notifications to other requesters only.*

- The **Select Group** field in the Add Level window is a combo box that defines which User Group’s Manager or members will be selected as the approving authority.
- The Approval Tool field in the Add Level window includes two checkboxes: Email and&#x20;  SMS - these are the mediums for sending the approval request to the approving&#x20;  authority.
- The **Timeout Period** field in the **Add Level** window is a combo box where you can select the timeout period to start an escalation. Default values are 30 minutes, 2 hours, and 24 hours. You can change the values in the combo box with the **approval.workflow\.level.timeout.period.values** parameter in the System Config. Man. The request gets escalated to the Escalation Authority after the specified period. If nothing is selected, no escalation is done.
- &#x20;The **Timeout Action** field in the **Add Level** window defines the action after the **Timeout Period**. Selecting **Escalate to Group Manager&#x20;**&#x6F;r **Escalate to Group&#x20;**&#x72;edirects the request to the **Group Manager** or the **Group** selected in the **Escalation** Field. The request expires after the timeout period if **Expire** is selected.
- The **Escalation Group** field in the Add Level window defines which User Group’s Manager or members will be selected for the approval escalation.

