Admin Guides / Approval policies
Removals and exceptions
Who approves a removal, the approval exception group, and approvals from the person who submits.
Who approves a removal
People remove access with the Remove Access and Remove Access Bundles forms, and with Remove Access beside each item on My Access. Set who approves those removals in Guided Setup step 7:
| Setting | Who approves |
|---|---|
| The person who has the access (default) | The holder. A person removing their own access is not asked again. |
| Their line manager | The holder's manager. If the manager is missing or inactive, the approval exception group. |
| The removal approval rules | The removal approval policy on the entitlement, then the collection, then the default removal policy from Guided Setup step 6. With none set anywhere, removing your own access needs no approval and removing someone else's asks their manager. |
| Nobody | No approval |
When the person removing the access would approve it themselves, or is a delegate of that approver, their request counts as the approval.
A removal that needs approval always gets a removal request, so the approval has a record to sit on. A removal that needs none is made the way Removals from reviews and My Access are made says in Guided Setup step 11: directly, or through a removal request every time, or only when the work is manual.
Removals of expired access follow a separate setting, Expired access is removed, in Guided Setup step 8.
The approval exception group
The approval exception group is the last resort when a rule cannot find anyone. Set it in Guided Setup step 6, usually to your identity and access management team.
It is asked when:
- a rule set to use a standby approver finds nobody, and its standby is unset, inactive or a group with no active members;
- a removal would go to the holder's manager, and the manager is missing or inactive.
One member's answer is enough, and the approval reads as the rule's name "by the exception approvers". The group is never asked about a request raised by or for one of its own members; that request stops instead. It is not asked when no policy applies at all, or when a rule is set to skip or stop.
If the group is not set, or has no active members, those requests stop before approval. Guided Setup shows step 6 in orange until the group is usable.
Approval from the person who submits
When the person who submits a request is also one of its approvers, Guided Setup step 6 decides what happens:
| Setting | What happens |
|---|---|
| Ask them (default) | They approve like any other approver |
| Their submission counts as their approval | Their stage is recorded as approved by them when they submit |
Bundle proposals
Proposals made with Onboard an Access Bundle have their own approvers: the bundle approvers group, then each entitlement owner. See Propose a bundle.