Account Based Approval Mechanism
the approval mechanism is activated for each account and sub account under the group different user groups can be assigned as managers for account approvals approvals can be made through the kron pam gui, by email, or through the kron pam mobile application all users except the password vault admin users docid\ aygy1uogprlzqyu9lr5mi are forced to go through the approval mechanism even if a user group has permission for an account or group, its members must first get approval account & group creator users docid 6bihm0e6qt0eshtdpqmwy also need to get approval for the accounts they created in the password vault tree structure, approval for sub accounts can be obtained from any parent group on the tree a multi level approval structure can be activated for additional checks and guardrails in addition, escalation can be configured for managers at each level if the managers at any level with pre configured escalation fail to approve/reject a request, the request is forwarded to substitute managers the following parameters in the system configuration manager govern the approval mechanism parameter name parameter value description sapm approval workflow accountbasedmanager the parameter is defined to activate the approval mechanism sapm account manager level count 3 (default is 2) passes the approval structure to the multi level structure