Manage application access requests
Enabling the Workflow feature for an application allows end users to send requests for access to the application to designated users or roles for approval. Approvers can grant access to the application permanently or for a specified time window. Granting access to the application means the users receive the View, Run, and Automatically Deploy permissions.
Configure a request and approval workflow
As a member of the sysadmin role or a role with the Role Management administrative right, you can configure roles for all other users. Initially, only the members of the sysadmin role have the ability to enable a “request and approval” workflow and can configure the workflow for selected applications, specify the users or roles with authority to approve access requests, and identify the role or roles to which users will be assigned if their request is approved.
At a high level, the steps involved in configuring a workflow are these:
- Create one or more roles that can enable a “request and approval” workflow.
- Create one or more roles that can approve access requests for the applications that have a “request and approval” workflow.
- Select an application and click Workflow to select the role into which requesters who are approved will be placed.
- Select the user or role with authority to approve requests.
If the Requestor’s Manager is the only approver in the approver list and the user has no manager, the request will be approved. If this is not desirable, verify that your users have a manager (refer to Add CyberArk Cloud Directory Users for more information) or add other users or roles to the approver list.
The first few steps in configuring the “request and approval” workflow are optional and involve creating one or more roles for users who are allowed to define a “request and approval” workflow for applications and the roles that can approve access requests. These steps are optional because you can choose to only allow members of the sysadmin role to be the users permitted to configure a workflow and members of the sysadmin role can assign approval authority to individual users without creating any approval roles. In most cases, however, creating roles for different sets of users provides greater flexibility and helps to reduce the number of requests left pending an approval.
If you don’t create any intermediary roles with the appropriate administrative rights to enable a workflow, only members of the sysadmin role will be able to configure any “request and approval” workflow you might want to implement.
In most cases, if you are configuring a request and approval workflow for applications, you should create at least one role for users who are allowed to add, modify, or remove applications and who have permission to change which roles are assigned to a specific applications. If you don’t create a role with the Application Management and Role Management rights, only members of the sysadmin role can configure the “request and approval” workflow for applications.
To configure roles that can enable a workflow
- Log in to the Admin Portal.
- Click Core Services > Roles.
Click Add Role or select an existing role to display the role details.
If you are creating a new role, you must provide at least a unique name for the role.
- Click Members, then click Add.
- Type a search string to search for and select users and groups for this role.
- Click Administrative Rights, then click Add.
Select the appropriate rights, then click Add.
For example, if you are creating a role with permission to enable a workflow for access to applications, select Application Management and Role Management. You can select any additional rights you want included in this role, but you must select at least one of the required administrative rights.
- Click Save to save the role.
Create roles for approvers
You can assign approval authority to individual users. However, in most cases, creating “approver” roles for different sets of users provides greater flexibility and helps to reduce the number of requests left pending an approval. If you don’t create any intermediary roles with the appropriate administrative rights to approve access requests, only members of the sysadmin role will be able to approve access requests. You can follow the same steps described in Create roles for workflow administration to create roles for approvers.
Keep in mind that if you are creating a role with permission to approve access requests for applications, you should include the Application Management and Role Management rights. You can select any additional rights you want included in this role.
As a member of the
sysadmin role or a role with Application Management and Role Management administrative rights, you can configure a request and approval workflow for any application.
- In the Admin Portal, click the Apps tab, then select a specific application for which you want to configure a request and approval workflow.
Click Workflow, then select Enable workflow for this application.
- Click Add (above) and select an Approver Type from the list (below).
- Click Add again to finish adding the approver type to the list.
If you want to have more than one approval before access to the app is granted, repeat the previous two steps.
Adding steps can be repeated as many times as desired to reflect the required steps in your approval process.When multiple approval steps are added, approval is needed from all listed approvers before access is granted. A rejection at any level results in the request being rejected. If the requester’s manager is not known, the request proceeds to the next step as though it had been approved. The next approver in the list is notified that the manager was not known, and therefore there has not yet been any approval or rejection of the request.
After you have configured the workflow for an application, users can request access to the application through the User Portal.
Request access to an application
Any user with an account in CyberArk Identity can request access to applications with workflow enabled. No special privileges are required to make requests.
Sign in to the CyberArk Identity User Portal .
Click the Apps tab, if needed.
Click Add Apps.
Click Apps > Add Web Apps.
Type a search string to find the application of interest in the catalog, then click Request.
Only applications with workflow enabled display a Request button.
Select either Permanent or Windowed in the Assignment Type drop-down menu.
Assignment type Description
If the request is granted, the user will have access to the app for an indefinite time period, or until it is revoked by an administrator.
If the request is granted, the user will have access to the app for the specified window, or until it is revoked by an administrator.
(Optional) Select the start and end date and time if the request is for a windowed assignment type.
Type the business reason for requesting access to the application, then click Submit to continue.
Click Close to close the App Catalog.
An email notification of your request is sent directly to the designated approver and a Requests tab will be visible the next time you go to the User Portal. You can click the Requests tab to see the status of your request. You will also receive an email notification when you request is approved or rejected. If your request was approved, the email will include a link to open the User Portal .
You can view request status and history in the User Portal, or if you have appropriate administrative rights you can view requests in the Admin Portal. The Requests tab is only available if you made a request or you are a designated approver for a request.
Regardless of the entry point for viewing the Requests tab, the list of requests includes the following information:
- Description provides a brief summary of the request indicating the type of access or application requested.
- Status displays the current status of the request as Pending, Approved, Rejected, or Failed.
You can review the request details to see the reason the request failed. For example, a request might fail if the email address for the approver or requester is invalid. A failed request might also indicate that the time allowed for taking the requested action has expired. For example, assume the request was for permission to use the
rootaccount to log on to a resource and the request was approved with a duration of 60 minutes. If the requester did not log on within 60 minutes of the request approval, the request status will display Failed.
Posted displays the date and time of the most recent activity for each request.
Approver displays the user or role designated for approving access requests if the approval is pending or the specific user who approved or rejected the request if the request has been resolved.
Requester displays the user who submitted the request.
Latest Log Entry displays the most recent information recorded for the request.
Respond to application access requests
There are no special privileges required to respond to requests. Anyone with access to CyberArk Identity can be designated as an approver.
If you are a designated approver for requests, you receive an email notification for requests. You can click the View Request link in the email to view the request details and the options to approve or reject the request.
Click Approve to approve the request and grant access to the application.
If you click OK to continue with the approval, the request details are updated with the date and time the request was resolved and the approved status.
Click Reject to reject the request and type the reason you are rejecting the request.
If you click OK to continue with the rejection, the request details are updated with the reason the request was rejected, the date and time the request was resolved, and the rejected status.
After you respond to the request, the Requests tab is also updated with the latest activity and email is sent to the requester as notification of your response to the request.
Access the request details by clicking View Request in the email notification, the Requests tab in the User Portal, or selecting Core Services > Requests and then clicking the request in the Admin Portal.
The Approve Request window appears.
Click either Approve or Reject to respond to the request.Approve
Click Approve to approve the request and grant the requester the necessary permissions to the object.
The Approve Request window appears.
Select either Permanent or Windowed in the Assignment Type drop-down menu.
- Permanent - Grants the user access to the app for an indefinite time period, or until you revoke access.
- Windowed - Grants the user access to the app for the specified window, or until you revoke access.
(Optional) Select the start and end date and time if the approval is for a windowed assignment type.
You can select a windowed approval regardless of the assignment type requested by the user. For example, you can approve access for a windowed time period if the user requested permanent access, or you can change the time window if the user requested windowed access.
The request details are updated with the date and time the request was resolved and the approved status.
Click Reject to reject the request and type the reason you are rejecting the request. If you click Submit to continue with the rejection, the request details are updated with the reason the request was rejected, the date and time the request was resolved, and the rejected status.