Password Retrieval Second-Level Approval Notifications
a two level approval mechanism can be set up for the desired user groups with a device group realm that contains the device where the vault account originates from these user groups should have the sapm second level approval requirement function group defined in their portal functions realm to do so, follow these steps navigate to policy > portal functions set the realm between the sapm second level approval requirement function group and the user group of the user that will need the second level approval when a user who requires two level approval attempts to retrieve an account password, a vault password approval request email is sent to the users listed below user groups with the full control permission over the vault account that requested the approval user groups with the single connect sapm admin and the single connect sapm network admin portal functions single connect sapm admin grants the right to manage all vault accounts and view all logs single connect sapm network admin grants the right to manage and view all vault accounts of devices the user has access to via device realm settings to set up managerial approval for account password retrieval navigate to policy > portal functions set the function realm containing the sapm admin function group and the user group of the user that should be able to provide first approval for all password retrieval requests and/or set the function realm containing the sapm network admin function group and the user group of the user that will be able to provide first approval for all password retrieval requests related to the devices in their device group realms only if a user fitting any of the above criteria approves the initial request, a password vault approval request email is sent to the second level approvers, who are members of user groups with the single connect sapm secondlevel admin and single connect sapm secondlevel network admin portal functions single connect sapm secondlevel admin grants the right to give second level approval for all password vault accounts and view all logs single connect sapm secondlevel network admin grants the right to give second level approval for all vault accounts of devices the user has access to via device realm settings to set up two level managerial approval for account password retrieval navigate to policy > portal functions set the function realm containing the sapm second level admin function group and the user group of the user that should be able to provide second approval for all password retrieval requests and/or set the function realm containing the sapm network admin function group and the user group of the user will be able to provide second level approval for all password retrieval requests related to the devices in their device group realms only if a user from these lists approves the second level request, the requester receives an email and can proceed to password checkout if any of the authorizers deny the request, informational emails are sent to all participants, and the request is terminated