Requesting and Approving Role Memberships
PrivX users can request granting or revoking role memberships for themselves or for other users.
Before users can request role membership changes, configure a workflow for the role. For more information, see Managing Workflows.
Role membership request considerations:
- Only users who have the required approver role can submit a decision. Users cannot approve their own requests.
- A request must receive all required approvals before PrivX applies it. One denial rejects the entire request.
- To remove membership granted by role rules, change the rules of the role.
- OpenID Connect users can request role membership only when Expire Implicit Roles is enabled for their OIDC directory. For more information, see OpenID-Connect (OIDC) Authentication.
- If the approver roles configured in a workflow change, members of the previously configured approver roles can still approve existing requests.
Requesting Role Membership
To submit a request:
- In Requests → My Requests, select New Request and specify:
- The user whose role membership you want to change.
- The role membership to grant or revoke.
- Under Membership, select the membership duration. PrivX includes this information in the mobile role request notification sent to approvers.
- In Justification for the Request, enter a meaningful explanation to help approvers evaluate the request.
- Submit the request.
You can review the status of your requests in Requests → My Requests.
Approving Role Membership Requests
PrivX users can approve or deny requests in either of the following ways:
- In the PrivX Web UI, on the Requests → Approvals page select the request to submit a decision.
- In PrivX Authorizer, if mobile approval is enabled for the workflow and the approver’s paired device is subscribed to mobile approvals.
Decisions submitted in PrivX Authorizer may take some time to appear in the PrivX Web UI.
Revoking Approvals
Any assigned approver can revoke an active approval.
To revoke an approval:
- On Requests → Approvals, open the approval you want to revoke.
- In the Request Approval, click Revoke Role.