Account Based Approval Mechanism
The approval mechanism is activated for each account and sub-account under the group. Different user groups can be assigned as managers for account approvals. Approvals can be made through the Kron PAM GUI, by email, or through the Kron PAM mobile application. All users except the Password Vault Admin Usersadmin user are forced to go through the approval mechanism. Even if a user group has permission for an account or group, its members must first get approval.Account & Group Creator UsersCreator users also need to get approval for the accounts they created. In the Password Vault Tree structure, approval for sub-accounts can be obtained from any parent group on the tree.
A multi-level approval structure can be activated for additional checks and guardrails. In addition, escalation can be configured for managers at each level. If the managers at any level with pre-configured escalation fail to approve/reject a request, the request is forwarded to substitute managers.
The following parameters in the System Configuration Manager govern the approval mechanism:
Parameter Name | Parameter Value | Description |
|---|---|---|
sapm.approval.workflow | AccountBasedManager | The parameter is defined to activate the approval mechanism. |
sapm.account.manager.level.count | 3 (Default is 2) | Passes the approval structure to the multi-level structure. |