WardeDocs User Guides Admin Guides warde.app

Admin Guides / Approval policies

Removals and exceptions

Who approves a removal, the approval exception group, and approvals from the person who submits.

Who approves a removal

People remove access with the Remove Access and Remove Access Bundles forms, and with Remove Access beside each item on My Access. Set who approves those removals in Guided Setup step 7:

SettingWho approves
The person who has the access (default)The holder. A person removing their own access is not asked again.
Their line managerThe holder's manager. If the manager is missing or inactive, the approval exception group.
The removal approval rulesThe removal approval policy on the entitlement, then the collection, then the default removal policy from Guided Setup step 6. With none set anywhere, removing your own access needs no approval and removing someone else's asks their manager.
NobodyNo approval

When the person removing the access would approve it themselves, or is a delegate of that approver, their request counts as the approval.

A removal that needs approval always gets a removal request, so the approval has a record to sit on. A removal that needs none is made the way Removals from reviews and My Access are made says in Guided Setup step 11: directly, or through a removal request every time, or only when the work is manual.

Removals of expired access follow a separate setting, Expired access is removed, in Guided Setup step 8.

The approval exception group

The approval exception group is the last resort when a rule cannot find anyone. Set it in Guided Setup step 6, usually to your identity and access management team.

It is asked when:

One member's answer is enough, and the approval reads as the rule's name "by the exception approvers". The group is never asked about a request raised by or for one of its own members; that request stops instead. It is not asked when no policy applies at all, or when a rule is set to skip or stop.

If the group is not set, or has no active members, those requests stop before approval. Guided Setup shows step 6 in orange until the group is usable.

Approval from the person who submits

When the person who submits a request is also one of its approvers, Guided Setup step 6 decides what happens:

SettingWhat happens
Ask them (default)They approve like any other approver
Their submission counts as their approvalTheir stage is recorded as approved by them when they submit

Bundle proposals

Proposals made with Onboard an Access Bundle have their own approvers: the bundle approvers group, then each entitlement owner. See Propose a bundle.

Warde is a ServiceNow scoped application, x_66256_warde. These guides describe the current release. Questions go to [email protected].

ServiceNow is a trademark of ServiceNow, Inc. SailPoint, IdentityIQ and Identity Security Cloud are trademarks of SailPoint Technologies, Inc. Microsoft and Microsoft Entra are trademarks of the Microsoft group of companies.