Secret Data Vault Second-Level Approval Notifications
Two-level approval can be set up for specific user groups. These user groups should have a Secret Data Vault Second Level Approval Requirement function group defined in their Portal Functions Realm. To do so, follow these steps:
- Navigate to Policy Control > Portal Functions.
- Set the realm between the Secret Data Vault Second Level Approval Requirement function group and the user group of the user that needs the second-level approval.
When a user solicits access to secret data that requires two-level approval, a Secret Data Approval Request email is sent to the following:
- User groups with the sc.secret.data.vault.admin portal function (or Secret Data Vault Admin function group)
- User groups with the FULL_CONTROL permission for the Secret Data Vault account that requested the approval
These additional steps should be followed:
- Navigate to Policy Control > Portal Functions.
- Set the realm between the Secret Data Vault Admin function group and the user group of the user that will give first approval for all password retrieval requests.
If a user from these lists approves the initial request, a Secret Data Vault Approval Request email is sent to the second-level approvers, i.e. the user groups with the sc.secret.data.vault.secondlevel.admin portal function, or the Secret Data Vault Second Level Admin function group in their Portal Functions realm.
Following these steps to set the necessary portal functions:
- Navigate to Policy Control > Portal Functions.
- Set the realm between the Secret Data Vault Second Level Admin function group and the user group of the user that will give second approval for all password retrieval requests.
If such a user approves the second-level request, the requester receives an approval email and can see the secret data.
If any of the authorizers deny the request, informational emails are sent to all the participants, and the request is terminated.