WardeDocs User Guides Admin Guides warde.app

Admin Guides / Approval policies

Build an approval policy

Create and test approval policies in the Approval Policy Wizard, with stages, rules, conditions and standby approvers.

Open the wizard

Open Warde > Approval Policy Wizard, select Build a policy in Guided Setup step 5, or select Open in policy wizard on a policy record in the Admin Workspace. Without a policy named, the wizard lists every policy and offers Create a policy. It needs the Warde administrator role.

A new policy is active as soon as you name it. The wizard has four steps.

1. Name the policy

Give it a name approvers and administrators will recognise, such as Manager, then application owner. The name appears in approval records and on every record that uses the policy.

The Name the policy step of the Approval Policy Wizard, with the name Manager, then the owner, a description, and Active ticked
Step 1: name the policy.

2. Design the stages

Add stages in the order they should run, and one or more rules in each stage. Rules in the same stage are asked at the same time; the next stage starts once every rule in the stage before it has approved.

The Design the stages step for the High risk access policy: stage 1 the line manager, stage 2 a field on the collection's configuration item, stage 3 the Security Operations group, all must approve
Step 2: three stages, one rule in each.

Select Edit on a rule, or Add a rule to this stage, to set it:

A rule open for editing: approvers come from the entitlement owner, the standby approver is used if none is found, and a warning that no standby approver is set yet
A rule open for editing, with a warning that it has no standby approver.

For each rule:

SettingChoices
Approvers come fromLine manager, entitlement owner, collection approvers, entitlement approvers, a field on the collection's configuration item, a named person, or a group. See Approvers.
Role filterFor collection and entitlement approvers only: ask only approvers tagged Business, Technical or Security. Empty means any.
How many must approveAny one of them, or all of them
LabelLine manager, Technical, Business or Elevated. It names the approval in records and messages and does not change who approves.
ConditionRun the rule only for request lines that match, such as entitlement risk is high or account type is admin. Empty runs it every time.
When the rule finds nobodyUse a standby approver, skip the rule, or stop the request

Standby approvers. For any source other than a named person or group, the rule's person and group fields are its standby: who approves when the source finds nobody. If the standby cannot act either, the approval exception group is asked. Using a standby is written to the audit history, because no rule chose that approver.

Skip moves on as if the rule had approved. Stop ends the request before approval, as described in When nobody can approve.

Inactive people, and groups with no active members, never count as approvers.

3. Test the policy

Choose a real entitlement and a real person, then select Run the preview. The wizard shows who would approve at each stage, found the same way as for a real request. Nothing is created and nobody is told.

The Test the policy step with SAP FI Posting requested for Jane Smith, showing Morgan Lee approving at stage 1 and Priya Natarajan at stage 2
Step 3: who would approve a real request.

Two things a preview cannot show: a condition on requested item fields never matches in a preview, and a real request with several items can have more stages than the preview, because their stages are combined.

4. Where it applies

Lists everything that uses the policy: entitlements, collections, access bundles and the instance defaults. A change applies to every request submitted after you save it.

The Where it applies step, counting the entitlements, collections and access bundles that use the policy, and noting that it is the instance-wide default
Step 4: everything that uses the policy.

Example policies

NeedStages
Everyday accessStage 1: line manager, any one
Sensitive accessStage 1: line manager. Stage 2: entitlement owner, standby a named owner group.
Extra check only for high-risk accessStage 1: line manager. Stage 2: collection approvers tagged Security, condition entitlement risk is high, skip if nobody is found.
Privileged accountsStage 1: line manager. Stage 2: a privileged access group, all must approve, condition account type is admin.
LicencesStage 1: line manager. Stage 2: a licence approver group, condition entitlement is licensing bound.

Attach a policy to a collection in Collection Onboarding step 4, to an entitlement on its record or drawer, to a bundle on its record, or make it the instance default in Guided Setup step 6.

Policy health

The Approval policy health tab of the Admin Workspace's Access health dashboard counts the gaps that make requests stop or skip:

Each count opens the list behind it.

Warde is a ServiceNow scoped application, x_66256_warde. These guides describe the current release. Questions go to [email protected].

ServiceNow is a trademark of ServiceNow, Inc. SailPoint, IdentityIQ and Identity Security Cloud are trademarks of SailPoint Technologies, Inc. Microsoft and Microsoft Entra are trademarks of the Microsoft group of companies.